ESAFENET CDG是一套文档安全管理系统。 ESAFENET CDG V3和V5版本中存在任意文件下载漏洞,该漏洞源于程序没有正确地处理‘InstallationPack’参数。攻击者可借助download.jsp文件中的‘fileName’参数利用该漏洞无需登录便可下载任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9632.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2019-9637 | PHP 权限许可和访问控制问题漏洞 | |
| CVE-2019-9638 | PHP 缓冲区错误漏洞 | |
| CVE-2019-9639 | PHP 缓冲区错误漏洞 | |
| CVE-2019-9640 | PHP 缓冲区错误漏洞 | |
| CVE-2019-9641 | PHP 缓冲区错误漏洞 | |
| CVE-2019-9636 | Python 信任管理问题漏洞 | |
| CVE-2018-20187 | Botan 安全漏洞 | |
| CVE-2019-9627 | CyberArk Software CyberArk Endpoint Privilege Manager 缓冲区错误漏洞 | |
| CVE-2019-9634 | Google Golang 代码问题漏洞 | |
| CVE-2019-9633 | GNOME Glib 输入验证错误漏洞 | |
| CVE-2019-9631 | Poppler 缓冲区错误漏洞 |
No comments yet