curl 是一个开放源码工具,采用URL语法发送/接收文件。 curl 7.20.0至7.21.1版本在使用--remote-header-name或者-J选项时存在绝对路径遍历漏洞。远程服务器可以通过使用"\"(反斜杠)作为Content-disposition HTTP头中的路径组件分隔符创建或者覆盖任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2010-2891 | libsmi lib/smi.c文件smiGetNode函数缓冲区溢出漏洞 | |
| CVE-2010-3711 | Pidgin libpurple输入验证漏洞 | |
| CVE-2010-3712 | Joomla!多个跨站脚本攻击漏洞 | |
| CVE-2010-3713 | UseBB rss.php文件权限许可和访问控制漏洞 | |
| CVE-2010-3765 | Mozilla Firefox/Thunderbird/SeaMonkey JavaScript缓冲区溢出漏洞 | |
| CVE-2010-3933 | Ruby on Rails输入验证漏洞 | |
| CVE-2010-4096 | Monkeysphere 'share/ma/keys_for_user'代码注入漏洞 | |
| CVE-2010-4097 | Avatic Aardvark Topsites PHP index.php文件多个跨站脚本攻击漏洞 | |
| CVE-2010-4098 | monotone设计错误漏洞 | |
| CVE-2010-4099 | NitroSecurity NitroView ESM ess.pm文件输入验证漏洞 |
No comments yet