Red Hat JBoss Enterprise Application Platform(EAP)是美国红帽(Red Hat)公司的一套开源的、基于J2EE的中间件平台。该平台主要用于构建、部署和托管Java应用程序与服务。 Red Hat JBoss Enterprise Application Platform 4.2版本至4.2.0.CP09之前版本、4.3版本至4.3.0.CP08之前版本存在权限许可和访问控制问题漏洞。攻击者利用该漏洞可以访问敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Red Hat JBoss Enterprise Application Platform 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 is susceptible to sensitive information disclosure. A remote attacker can obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2010/CVE-2010-1429.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2010-1596 | SITracke Support Incident Tracker授权问题漏洞 | |
| CVE-2010-1587 | Apache ActiveMQ URL请求源码泄露漏洞 | |
| CVE-2010-1586 | HP系统管理主页RedirectUrl参数URI重新定向漏洞 | |
| CVE-2010-1585 | Mozilla Firefox/Thunderbird/SeaMonkey nsIScriptableUnescapeHTML.parseFragment方法输入验证漏洞 | |
| CVE-2010-1428 | Red Hat JBoss企业应用平台多个漏洞 | |
| CVE-2010-1038 | HP Systems Insight Manager 未明权限提升漏洞 | |
| CVE-2010-1037 | HP Systems Insight Manager 未明跨站请求伪造漏洞 | |
| CVE-2010-1036 | HP Systems Insight Manager 未明跨站脚本攻击漏洞 | |
| CVE-2010-0738 | Red Hat JBoss Enterprise Application Platform 权限许可和访问控制问题漏洞 | |
| CVE-2010-1588 | Vpasp Rocksalt International VP-ASP Shopping Cart 'shopsessionsubs.asp' Getwebsess函数SQL注入漏 | |
| CVE-2010-1595 | OCS Inventory NG 'ocsreports/index.php'多个SQL注入漏洞 | |
| CVE-2010-1594 | OCS Inventory NG 'ocsreports/index.php'多个跨站脚本攻击漏洞 | |
| CVE-2010-1593 | SilverStripe 多个跨站脚本攻击漏洞 | |
| CVE-2010-1592 | SiSoftware Sandra 'sandra.sys'输入验证漏洞 | |
| CVE-2010-1591 | Rising-Global瑞星杀毒软件IOCTL请求处理本地权限提升漏洞 | |
| CVE-2010-1590 | Vpasp Rocksalt International VP-ASP Shopping Cart 'shopsessionsubs.asp'跨站脚本攻击漏洞 | |
| CVE-2010-1589 | Vpasp Rocksalt International VP-ASP Shopping Cart 'shopsessionsubs.asp'目录遍历漏洞 |
No comments yet