Lenovo ThinkManagement Console 9.0.3版本的ServerSetup网络服务中的andesk/managementsuite/core/core.anonymous/ServerSetup.asmx中存在无限制文件上传漏洞。远程攻击者可利用该漏洞借助RunAMTCommand SOAP请求中的PutUpdateFileCore命令,通过上传带有可执行扩展名的文件执行任意代码,然后借助网站根目录的直接请求,访问文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2011-3361 | BackupPC 跨站脚本漏洞 | |
| CVE-2011-4320 | ejabberd拒绝服务漏洞 | |
| CVE-2011-4614 | TYPO3任意代码执行漏洞 | |
| CVE-2011-4923 | BackupPC ‘View.pm’ 跨站脚本漏洞 | |
| CVE-2011-5081 | BackupPC ‘RestoreFile.pm’ 跨站脚本漏洞 | |
| CVE-2012-1196 | Lenovo ThinkManagement Console 目录遍历漏洞 | |
| CVE-2012-1197 | ACDSee BMP图形文件处理远程堆缓冲区溢出漏洞 | |
| CVE-2012-1198 | Basic Analysis/Security Engine远程文件包含漏洞 | |
| CVE-2012-1199 | BASE 多个PHP远程文件包含漏洞 | |
| CVE-2012-1200 | Nova CMS多个远程文件包含漏洞 |
No comments yet