pktstat是软件开发者David Leonard所研发的一套实时网络流量查看工具。 pktstat 1.8.5版本的tmp_smtp.c文件中存在安全漏洞。本地攻击者可通过对/tmp/smtp.log文件实施符号链接攻击利用该漏洞覆盖任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2010-5109 | Libytnef ‘DecompressRTF’函数差一错误漏洞 | |
| CVE-2013-1803 | PHP-Fusion 多个SQL注入漏洞 | |
| CVE-2013-3736 | Best Practical Solutions Request Tracker MobileUI扩展跨站脚本漏洞 | |
| CVE-2013-4215 | Nagios Plugins 不安全临时文件创建漏洞 | |
| CVE-2013-6418 | PyWBEM 输入验证漏洞 | |
| CVE-2013-6444 | PyWBEM 输入验证漏洞 | |
| CVE-2013-7003 | LiveZilla 跨站脚本漏洞 | |
| CVE-2013-7034 | LiveZilla ‘setCookieValue()’ 函数远程PHP代码注入漏洞 | |
| CVE-2013-7375 | PHP-Fusion SQL注入漏洞 | |
| CVE-2014-0149 | Red Hat JBoss Web Framework Kit 跨站脚本漏洞 | |
| CVE-2014-0164 | Red Hat OpenShift Enterprise 加密问题漏洞 | |
| CVE-2014-3220 | F5 BIG-IQ 信任管理漏洞 | |
| CVE-2014-0469 | Debian patch for xbuffy 基于栈的缓冲区溢出漏洞 | |
| CVE-2014-2916 | PhpList 跨站请求伪造漏洞 |
No comments yet