Ericsson Drutt Mobile Service Delivery Platform (MSDP)是瑞典爱立信(Ericsson)公司的一套为现场和非门户业务的服务交付平台(SDP)提供支持的业务支持系统。 Ericsson Drutt MSDP的Instance Monitor中存在目录遍历漏洞。远程攻击者可借助默认的URI中的‘..%2f’(点点编码的反斜杠)字符串利用该漏洞读取任意文件。以下版本受到影响:Ericsson Drutt MSDP 4版本,5版本和6版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | A PoC exploit for CVE-2015-2166 - Directory Traversal Vulnerability in Ericsson Drutt Mobile Service Delivery Platform (MSDP) | https://github.com/K3ysTr0K3R/CVE-2015-2166-EXPLOIT | POC Details |
| 2 | Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the default URI in the Instance Monitor. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2015/CVE-2015-2166.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2015-1843 | Red Hat docker package 输入验证漏洞 | |
| CVE-2015-2165 | Ericsson Drutt Mobile Service Delivery Platform Report Viewer 跨站脚本漏洞 | |
| CVE-2015-2167 | Ericsson Drutt Mobile Service Delivery Platform 输入验证漏洞 | |
| CVE-2015-2824 | WordPress Simple Ads Manager插件SQL注入漏洞 | |
| CVE-2015-0877 | C-BOARD Moyuku 任意文件上传漏洞 | |
| CVE-2015-1601 | Siemens SIMATIC STEP 7(TIA Portal)信息泄露漏洞 | |
| CVE-2015-1602 | Siemens SIMATIC STEP 7(TIA Portal)信息泄露漏洞 | |
| CVE-2014-6221 | IBM Rational ClearCase GSKit 加密问题漏洞 | |
| CVE-2015-0117 | IBM Domino LDAP Server 安全漏洞 | |
| CVE-2015-0119 | IBM Tivoli Storage Manager FastBack 任意代码执行漏洞 | |
| CVE-2015-0134 | IBM Domino SSLv2 缓冲区溢出漏洞 | |
| CVE-2015-0179 | IBM Domino Notes System Diagnostic 权限许可和访问控制漏洞 | |
| CVE-2015-1890 | IBM General Parallel File System 信息泄露漏洞 | |
| CVE-2015-1893 | IBM WebSphere DataPower XC10 权限许可和访问控制漏洞 |
No comments yet