NaviServer是一款使用C语言和Tcl语言编写的Web服务器。它支持反向代理、IPv6、动态线程池映射和基于OpenSSL的加密等功能。 NaviServer 4.99.4版本至4.99.19版本中的nsd/driver.c文件的‘ChunkedDecode’函数存在安全漏洞,该漏洞源于程序没有正确验证块的长度。远程攻击者可通过发送特制的分块传输请求利用该漏洞导致拒绝服务(进程崩溃)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-13121 | Submitty 输入验证错误漏洞 | |
| CVE-2020-13118 | Mikrotik-Router-Monitoring-System SQL注入漏洞 | |
| CVE-2020-13110 | kerberos package for Node.js 代码问题漏洞 | |
| CVE-2020-13109 | SETA Morita Shogi 64 缓冲区错误漏洞 |
No comments yet