Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-17105

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Zivif PR115-204-P-RS是一款网络摄像机设备。 Zivif PR115-204-P-RS 2.3.4.2103版本中存在命令注入漏洞。该漏洞源于外部输入数据构造可执行命令过程中,网络系统或产品未正确过滤其中的特殊元素。攻击者可利用该漏洞执行非法命令。

AI Predicted 9.8 Difficulty: Easy EPSS 84.56% · P100

Public Exploits 1

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-17105

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a cgi-bin/iptest.cgi?cmd=iptest.cgi&-time="1504225666237"&-url=$(reboot) request.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Zivif PR115-204-P-RS 操作系统命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Zivif PR115-204-P-RS是一款网络摄像机设备。 Zivif PR115-204-P-RS 2.3.4.2103版本中存在命令注入漏洞。该漏洞源于外部输入数据构造可执行命令过程中,网络系统或产品未正确过滤其中的特殊元素。攻击者可利用该漏洞执行非法命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2017-17105

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-17105

登录查看更多情报信息。

Exploits & Public PoCs for CVE-2017-17105 (1)

Mailing List Discussions for CVE-2017-17105 (1)

Other References for CVE-2017-17105 (1)

Same Patch Batch · n/a · 2017-12-18 · 27 CVEs total

CVE-2017-17651 PHP Scripts Mall Paid To Read Script SQL注入漏洞
CVE-2017-16997 GNU C Library 代码问题漏洞
CVE-2017-17733 Maccms 安全漏洞
CVE-2017-17731 Desdev DedeCMS SQL注入漏洞
CVE-2017-17730 Desdev DedeCMS SQL注入漏洞
CVE-2017-17727 Desdev DedeCMS 安全漏洞
CVE-2017-17740 OpenLDAP 安全漏洞
CVE-2017-17739 BrightSign Digital Signage(4k242)路径遍历漏洞
CVE-2017-17738 BrightSign Digital Signage(4k242)安全漏洞
CVE-2017-17737 BrightSign Digital Signage(4k242)跨站脚本漏洞
CVE-2017-17735 CMS Made Simple 安全漏洞
CVE-2017-17734 CMS Made Simple 信息泄露漏洞
CVE-2017-17741 Linux kernel 安全漏洞
CVE-2017-11562 MT4 Networks SenhaSegura Web Application 安全漏洞
CVE-2017-17649 PHP Scripts Mall Readymade Video Sharing Script 安全漏洞
CVE-2017-17645 Bus Booking Script SQL注入漏洞
CVE-2017-17643 FS Lynda Clone SQL注入漏洞
CVE-2017-14583 NetApp Clustered Data ONTAP 安全漏洞
CVE-2017-17721 ZUUSE BEIMS ContractorWeb .NET SQL注入漏洞
CVE-2017-17107 Zivif PR115-204-P-RS 安全漏洞

Showing top 20 of 27 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-17105

No comments yet


Leave a comment