xunfeng(巡风)是一套适用于企业内网的漏洞快速应急和资产扫描系统。anti-csrf decorator是其中的一个CSRF处理组件。 xunfeng 0.2.0版本中的anti-csrf decorator存在跨站请求伪造漏洞,该漏洞源于views/lib/AntiCSRF.py文件可以借助X-Forwarded-Host HTTP包头值覆盖request.host值。远程攻击者可借助Flash文件利用该漏洞修改配置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-16807 | Bro Kerberos protocol解析器安全漏洞 | |
| CVE-2018-16831 | New Digital Group Smarty 安全漏洞 | |
| CVE-2018-16836 | Rubedo theme组件路径遍历漏洞 | |
| CVE-2018-15898 | Subsonic Music Streamer for Android 安全漏洞 |
No comments yet