Paessler PRTG Network Monitor是德国Paessler公司的一套网络监控软件。该软件提供使用情况的监测、数据包嗅探、深入分析和简明的报告等功能。 Paessler PRTG Network Monitor 18.2.40.1683之前版本中存在安全漏洞。远程攻击者可通过发送特制的HTTP请求并覆盖/public/login.htm文件中的‘include’指令的属性项。攻击者可借助‘id’和‘users’参数利用该漏洞创建带有读写权限的用户账户(包括管理员账户)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Proof of concept for the vulnerability CVE-2018-19410 | https://github.com/himash/CVE-2018-19410-POC | POC Details |
| 2 | PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator). | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-19410.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-19420 | Cagintranet GetSimple CMS 安全漏洞 | |
| CVE-2018-19421 | Cagintranet GetSimple CMS 安全漏洞 | |
| CVE-2018-19423 | Codiad 安全漏洞 | |
| CVE-2018-19424 | ClipperCMS 安全漏洞 | |
| CVE-2018-19416 | Sysstat 缓冲区错误漏洞 | |
| CVE-2018-19417 | Contiki-NG MQTT服务器缓冲区错误漏洞 | |
| CVE-2018-19409 | Artifex Ghostscript 安全漏洞 | |
| CVE-2018-19411 | Paessler PRTG Network Monitor 权限许可和访问控制问题漏洞 | |
| CVE-2009-5153 | Novell NetWare 缓冲区错误漏洞 | |
| CVE-2018-19404 | YXcms 安全漏洞 | |
| CVE-2018-19406 | Linux kernel 安全漏洞 | |
| CVE-2018-19407 | Linux kernel 安全漏洞 | |
| CVE-2018-19422 | Subrion CMS 安全漏洞 |
No comments yet