Apache log4net是美国阿帕奇(Apache)基金会的一款日志输出工具。 Apache log4net 2.0.8之前版本中log4net配置文件的解析过程存在代码问题漏洞。攻击者可借助特制XML内容利用该漏洞迫使系统接受任意配置文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Apache log4net | Apache log4net up to 2.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Test application for CVE-2018-1285 alert for Solarwinds DLLs | https://github.com/alex-ermolaev/Log4NetSolarWindsSNMP- | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-12752 | Samsung移动设备安全漏洞 | |
| CVE-2020-7647 | Jooby 路径遍历漏洞 | |
| CVE-2020-5837 | Symantec Endpoint Protection 后置链接漏洞 | |
| CVE-2020-5836 | Symantec Endpoint Protection 安全漏洞 | |
| CVE-2020-5835 | Symantec Endpoint Protection Manager 竞争条件问题漏洞 | |
| CVE-2020-5834 | Symantec Endpoint Protection Manager 路径遍历漏洞 | |
| CVE-2020-5833 | Symantec Endpoint Protection Manager 缓冲区错误漏洞 | |
| CVE-2020-12790 | Seomatic 注入漏洞 | |
| CVE-2019-5500 | NetApp Service Processor和NetApp Baseboard Management Controller 安全漏洞 | |
| CVE-2020-12760 | OpenNMS Group OpenNMS 代码问题漏洞 | |
| CVE-2020-12785 | cPanel 安全漏洞 | |
| CVE-2020-12784 | cPanel 输入验证错误漏洞 | |
| CVE-2020-12754 | LG移动设备安全漏洞 | |
| CVE-2020-12753 | LG Mobile Devices With Android 缓冲区错误漏洞 | |
| CVE-2020-12743 | Gazie 安全漏洞 | |
| CVE-2020-12751 | Samsung Mobile Device 缓冲区错误漏洞 | |
| CVE-2020-12750 | Samsung移动设备安全漏洞 | |
| CVE-2020-12749 | Samsung移动设备缓冲区错误漏洞 | |
| CVE-2020-12748 | Samsung移动设备安全漏洞 | |
| CVE-2020-12747 | Samsung移动设备缓冲区错误漏洞 |
Showing top 20 of 29 CVEs. View all on vendor page → →
No comments yet