Sonatype Nexus Repository是美国Sonatype公司的一款存储库管理器,它主要用于管理、存储和分发软件等。 Sonatype Nexus Repository 3.21.2之前版本中存在安全漏洞。攻击者可利用该漏洞执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2020-10204 远程命令执行脚本 | https://github.com/zhzyker/CVE-2020-10204 | POC Details |
| 2 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Nexus%20Repository%20Manager%203%20extdirect%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2020-10204.md | POC Details |
| 3 | https://github.com/vulhub/vulhub/blob/master/nexus/CVE-2020-10204/README.md | POC Details | |
| 4 | Sonatype Nexus Repository Manager 3 up to and including 3.21.1 is vulnerable to Expression Language injection. An attacker authenticated with an administrative account can inject an EL expression into the user "roles" field of the coreui_User update endpoint, leading to remote code execution. This is a bypass of the fix for CVE-2018-16621. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10204.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-11457 | pfSense 跨站脚本漏洞 | |
| CVE-2020-10863 | Avast Antivirus 输入验证错误漏洞 | |
| CVE-2020-10862 | Avast Antivirus 安全漏洞 | |
| CVE-2020-10861 | Avast Antivirus 输入验证错误漏洞 | |
| CVE-2020-10860 | Avast Antivirus 缓冲区错误漏洞 | |
| CVE-2019-3944 | Parrot ANAFI 安全漏洞 | |
| CVE-2019-3945 | Parrot ANAFI 安全漏洞 | |
| CVE-2019-3942 | Advantech WebAccess 访问控制错误漏洞 | |
| CVE-2020-11455 | LimeSurvey 路径遍历漏洞 | |
| CVE-2020-11456 | LimeSurvey 跨站脚本漏洞 | |
| CVE-2020-10864 | Avast Antivirus 输入验证错误漏洞 | |
| CVE-2020-11449 | Technicolor 安全漏洞 | |
| CVE-2020-10231 | 多款TP-Link产品代码问题漏洞 | |
| CVE-2020-7948 | WordPress Auth0 安全漏洞 | |
| CVE-2020-7947 | WordPress Auth0 注入漏洞 | |
| CVE-2020-5391 | WordPress Auth0 跨站请求伪造漏洞 | |
| CVE-2020-6753 | WordPress Auth0 跨站脚本漏洞 | |
| CVE-2020-5392 | WordPress Auth0 跨站脚本漏洞 | |
| CVE-2020-11445 | 多款TP-LINK产品授权问题漏洞 | |
| CVE-2020-6096 | GNU glibc 数字错误漏洞 |
Showing top 20 of 41 CVEs. View all on vendor page → →
No comments yet