Novell iManager是美国Novell公司的一款基于WEB的应用程序,可以使用无线设备管理、配置Novell eDirectory对象。 iManager在Schema菜单下提供了一个功能允许创建类,类名称最长为32个字符。这个限制是由客户端在表单字段中将maxlength属性设置为32来强制的,但在服务端没有执行验证来确保用户所定义的类名称没有超过32个字符。已认证的用户可以通过篡改在创建新类时发送类名称的POST请求就可以触发栈溢出,导致覆盖返回地址和SEH,以当前用户(iManager工作
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2010-2504 | Splunk未明漏洞 | |
| CVE-2010-2470 | Mozilla Bugzilla 'Install/Filesystem.pm'信息泄露漏洞 | |
| CVE-2010-2231 | Moodle 'report/overview/report.php'跨站请求伪造漏洞 | |
| CVE-2010-2230 | Moodle 'lib/weblib.php'跨站脚本攻击漏洞 | |
| CVE-2010-2229 | Moodle 'blog/index.php'多个跨站脚本攻击漏洞 | |
| CVE-2010-2228 | Moodle MNET访问控制界面跨站脚本攻击漏洞 | |
| CVE-2010-1930 | Novell iManager FTF2单字节溢出错误 | |
| CVE-2010-1204 | Mozilla Bugzilla时间追踪功能信息泄露漏洞 | |
| CVE-2010-0180 | Mozilla Bugzilla 'Install/Filesystem.pm'信息泄露漏洞 | |
| CVE-2010-2506 | Linksys WAP54Gv3 固件'debug.cgi'跨站脚本攻击漏洞 | |
| CVE-2010-2505 | Saschart SasCam Webcam Server输入验证漏洞 | |
| CVE-2010-2507 | Joomla!组件Picasa2Gallery (com_picasa2gallery)目录遍历漏洞 | |
| CVE-2010-2503 | Splunk多个跨站脚本攻击漏洞 | |
| CVE-2010-2502 | Splunk多个目录遍历漏洞 | |
| CVE-2010-2515 | Joomla! 组件JFaq (com_jfaq) 'index.php'多个SQL注入漏洞 | |
| CVE-2010-2514 | Joomla!组件 JFaq (com_jfaq)跨站脚本攻击漏洞 | |
| CVE-2010-2513 | Joomla!组件JE Ajax Event Calendar (com_jeajaxeventcalendar)SQL注入漏洞 | |
| CVE-2010-2512 | 2daybiz Matrimonial Script 'customprofile.php'SQL注入漏洞 | |
| CVE-2010-2511 | 2daybiz Multi Level Marketing (MLM) Software 'viewnews.php'SQL注入漏洞 | |
| CVE-2010-2510 | 2daybiz Web Template Software 'customize.php'SQL注入漏洞 |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet