Canonical Ubuntu Metal as a Service(MAAS)是英国科能(Canonical)公司的一套云服务器部署和管理工具。该工具可对大量服务器的硬件环境进行集中部署并管理。 Ubuntu MAAS 1.9.2之前版本中的REST API存在跨站脚本漏洞,该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2014-1426 | get_file_by_name does not check owner | |
| CVE-2014-1428 | uuid.uuid1() is not suitable as an unguessable identifier/token | |
| CVE-2015-1316 | Juju Joyent provider uploads user's private ssh key by default | |
| CVE-2015-1320 | Probe-and-enlist for SeaMicro chassis writes password to the log | |
| CVE-2015-1326 | python-dbusmock arbitrary code execution or file overwrite when templates are loaded from | |
| CVE-2015-1327 | Content-hub DBUS API doesn't prevent confined apps from passing paths to files without acc | |
| CVE-2015-1340 | chmod race in doUidshiftIntoContainer | |
| CVE-2015-1341 | Apport privilege escalation through Python module imports | |
| CVE-2015-1343 | unity-scope-gdrive search feature logs search terms to syslog | |
| CVE-2016-1573 | Using a specially crafted fallback art property, scopes can execute arbitrary QML code in | |
| CVE-2016-1579 | UDM doesn't check for confinement before running post-processing commands | |
| CVE-2016-1584 | Unity8 converged application lifecycle allows background applications to use on-screen key | |
| CVE-2016-1586 | Oxide 输入验证错误漏洞 | |
| CVE-2016-1587 | Snapweb interface 访问控制错误漏洞 |
No comments yet