Argus Surveillance DVR是加拿大Argus Surveillance公司的一款硬盘录像机设备。 Argus Surveillance DVR 4.0.0.0版本中的WEBACCOUNT.CGI文件存在目录遍历漏洞。攻击者可借助‘RESULTPAGE’参数中的‘..%2F’利用该漏洞泄露文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Argus Surveillance DVR 4.0.0.0 devices allow unauthenticated local file inclusion, leading to file disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-15745.yaml | POC Details |
| 2 | None | https://github.com/Jasurbek-Masimov/CVE-2018-15745 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-14901 | EPSON iPrint application for Android 安全漏洞 | |
| CVE-2018-16239 | damiCMS 安全漏洞 | |
| CVE-2018-16238 | damiCMS 安全漏洞 | |
| CVE-2018-16237 | damiCMS 路径遍历漏洞 | |
| CVE-2018-16236 | cPanel 跨站脚本漏洞 | |
| CVE-2018-16234 | MorningStar WhatWeb 跨站脚本漏洞 | |
| CVE-2018-16233 | MiniCMS 跨站脚本漏洞 | |
| CVE-2018-16231 | Michael Roth Software Personal FTP Server 安全漏洞 | |
| CVE-2018-15480 | 多款myStrom WiFi产品安全漏洞 | |
| CVE-2018-15479 | 多款myStrom WiFi产品安全漏洞 | |
| CVE-2018-15478 | 多款myStrom WiFi产品安全漏洞 | |
| CVE-2018-15477 | myStrom WiFi Switch V1 安全漏洞 | |
| CVE-2018-15476 | 多款myStrom WiFi产品安全漏洞 | |
| CVE-2018-14903 | EPSON WF-2750打印机安全漏洞 | |
| CVE-2018-14902 | EPSON iPrint application for Android 安全漏洞 | |
| CVE-2018-16056 | Wireshark Bluetooth Attribute Protocol解析器注入漏洞 | |
| CVE-2018-14900 | EPSON WF-2750打印机安全漏洞 | |
| CVE-2018-14899 | EPSON WF-2750打印机安全漏洞 | |
| CVE-2018-11720 | Xovis PC2、PC2R和PC3传感器路径遍历漏洞 | |
| CVE-2018-11719 | Xovis PC2、PC2R和PC3传感器安全漏洞 |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet