anixis password reset client是 ANIXIS 3.22之前版本存在安全漏洞,该漏洞源于密码重置客户端定制GINA/CP模块允许远程攻击者通过欺骗来执行代码和升级特权。当客户端配置为使用HTTP时,它在打开浏览器窗口之前不会对预期的服务器进行身份验证。能够执行欺骗攻击的未经身份验证的攻击者可以重定向浏览器以在winlogin .exe进程上下文中执行。如果没有实施网络级身份验证,则可以通过RDP利用该漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2018-5354 | https://github.com/missing0x00/CVE-2018-5354 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-15595 | 4.3 MEDIUM | Zoho Application Control Plus 安全漏洞 |
| CVE-2020-15594 | 4.3 MEDIUM | Zoho Application Control Plus 信息泄露漏洞 |
| CVE-2020-26154 | libproxy 缓冲区错误漏洞 | |
| CVE-2020-26137 | urllib3 注入漏洞 | |
| CVE-2020-26150 | Logaritmo Aware CallManager 信息泄露漏洞 | |
| CVE-2020-13794 | Linux kernel 信息泄露漏洞 | |
| CVE-2018-5353 | ZOHO ManageEngine ADSelfService Plus 安全漏洞 | |
| CVE-2020-24570 | MB CONNECT LINE mymbCONNECT24和mbCONNECT24 SQL跨站请求伪造漏洞 | |
| CVE-2020-24569 | MB CONNECT LINE mymbCONNECT24和knximport SQL注入漏洞 | |
| CVE-2020-25763 | Seat Reservation System 代码问题漏洞 | |
| CVE-2020-25762 | Seat Reservation System SQL注入漏洞 | |
| CVE-2020-25761 | Projectworlds Visitor Management System 跨站脚本漏洞 | |
| CVE-2020-25760 | Projectworlds Visitor Management System SQL注入漏洞 | |
| CVE-2020-13658 | Lansweeper 跨站请求伪造漏洞 | |
| CVE-2020-26148 | md4c 安全漏洞 | |
| CVE-2020-20800 | MetInfo SQL注入漏洞 | |
| CVE-2020-26043 | Hoosk CmS 跨站脚本漏洞 | |
| CVE-2020-8243 | Pulse Secure Pulse Connect Secure 代码注入漏洞 | |
| CVE-2020-26042 | Hoosk CMS SQL注入漏洞 | |
| CVE-2020-8256 | Pulse Secure Connect Secure 代码问题漏洞 |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet