Grafana是Grafana实验室的一套提供可视化监控界面的开源监控工具。该工具主要用于监控和分析Graphite、InfluxDB和Prometheus等。 Grafana 6.7.1及之前版本中存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Proof of concept for CVE-2020-11110, for educational purpose only | https://github.com/AVE-Stoik/CVE-2020-11110-Proof-of-Concept | POC Details |
| 2 | Grafana through 6.7.1 contains an unauthenticated stored cross-site scripting vulnerability due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-11110.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-7695 | 5.3 MEDIUM | HTTP Response Splitting |
| CVE-2020-7694 | 3.7 LOW | Log Injection |
| CVE-2020-12845 | Cherokee 代码问题漏洞 | |
| CVE-2020-12460 | OpenDMARC 缓冲区错误漏洞 | |
| CVE-2020-12880 | Pulse Secure Pulse Connect Secure和Pulse Policy Secure 信息泄露漏洞 | |
| CVE-2020-15593 | Riverbed Technology SteelCentral Aternity Agent 安全漏洞 | |
| CVE-2020-15592 | Riverbed Technology SteelCentral Aternity Agent 路径遍历漏洞 | |
| CVE-2020-9251 | Huawei Mate 20 授权问题漏洞 | |
| CVE-2020-9077 | Huawei P30 信息泄露漏洞 | |
| CVE-2020-15953 | LibEtPan 注入漏洞 | |
| CVE-2020-15954 | KDE KMail 安全漏洞 |
No comments yet