TLS是IETF标准组织的一个传输层安全性协议,目的是为互联网通信提供安全及数据完整性保障。 TLS协议1.2及之前版本中存在加密问题漏洞,该漏洞源于当服务器启用DHE_EXPORT密码套件时,程序没有正确传递DHE_EXPORT选项。攻击者可通过重写ClientHello(使用DHE_EXPORT取代DHE),然后重写ServerHello(使用DHE取代DHE_EXPORT),利用该漏洞实施中间人攻击和cipher-downgrade攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | ✨ HAProxy ve Keepalived konusunu load balancer ve cluster'a ek olarak güvenlik(zayıf SSL/Kripto Kullanımı (LOGJAM) (CVE-2015-4000) zafiyeti önlemi) ve yüksek yüklere karşı ele alır. | https://github.com/fatlan/HAProxy-Keepalived-Sec-HighLoads | POC Details |
No public POC found.
Login to generate AI POC| CVE-2012-1978 | Simple PHP Agenda 跨站请求伪造漏洞 | |
| CVE-2015-3647 | WordPress WP Photo Album Plus插件输入验证漏洞 | |
| CVE-2015-4018 | WordPress FeedWordPress插件SQL注入漏洞 | |
| CVE-2015-3911 | Huawei E587 Mobile WiFi 权限许可和访问控制漏洞 | |
| CVE-2015-3912 | Huawei E355s Mobile WiFi 信息泄露漏洞 | |
| CVE-2015-0741 | Cisco Prime Central for Hosted Collaboration Solution 跨站请求伪造漏洞 | |
| CVE-2015-0742 | Cisco Adaptive Security Appliances Software Protocol Independent Multicast 代码注入漏洞 | |
| CVE-2015-3036 | Linux kernel KCodes NetUSB模块基于栈的缓冲区溢出漏洞 |
No comments yet