lighttpd是德国软件开发者Jan Kneschke所研发的一款开源的Web服务器,它的主要特点是仅需少量的内存及CPU资源即可达到同类网页服务器的性能。 lighttpd 1.4.50之前的版本中的mod_alias.c文件的‘mod_alias_physical_handler’函数存在路径遍历漏洞。远程攻击者可利用该漏洞访问文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | PoC for a security: potential path traversal with specific configs, if `mod_dirlisting` were enabled, which is not the default, this would result in listing the contents of the directory above the alias.. | https://github.com/iveresk/cve-2018-19052 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-19061 | Desdev DedeCMS SQL注入漏洞 | |
| CVE-2018-19075 | Foscam C2和Opticam i5 安全漏洞 | |
| CVE-2018-19076 | Foscam C2和Opticam i5 安全漏洞 | |
| CVE-2018-19077 | Foscam OptiCam i5 安全漏洞 | |
| CVE-2018-19078 | Foscam OptiCam i5 安全漏洞 | |
| CVE-2018-19079 | Foscam OptiCam i5 访问控制错误漏洞 | |
| CVE-2018-19080 | Foscam OptiCam i5 跨站脚本漏洞 | |
| CVE-2018-19081 | Foscam OptiCam i5 操作系统命令注入漏洞 | |
| CVE-2018-19082 | Foscam OptiCam i5 缓冲区错误漏洞 | |
| CVE-2018-19083 | WeCenter ‘htmlspecialchars_decode’函数跨站脚本漏洞 | |
| CVE-2018-19074 | Foscam C2和Opticam i5 安全漏洞 | |
| CVE-2018-19058 | Poppler ‘abort()’ 函数输入验证错误漏洞 | |
| CVE-2018-19059 | Poppler ‘EmbFile::save2’函数安全漏洞 | |
| CVE-2018-19060 | Poppler 安全漏洞 | |
| CVE-2018-19056 | Pandao Editor.md 跨站脚本漏洞 | |
| CVE-2018-19057 | SimpleMDE 跨站脚本漏洞 | |
| CVE-2018-19047 | mPDF 安全漏洞 | |
| CVE-2018-19053 | PbootCMS 安全漏洞 | |
| CVE-2018-19050 | MetInfo 跨站脚本漏洞 | |
| CVE-2018-19051 | MetInfo 跨站脚本漏洞 |
Showing top 20 of 40 CVEs. View all on vendor page → →
No comments yet