OpenSSH(OpenBSD Secure Shell)是加拿大OpenBSD计划组的一套用于安全访问远程计算机的连接工具。该工具是SSH协议的开源实现,支持对所有的传输进行加密,可有效阻止窃听、连接劫持以及其他网络级的攻击。 OpenSSH 8.3p1及之前版本中的scp的scp.c文件存在操作系统命令注入漏洞。该漏洞源于外部输入数据构造操作系统可执行命令过程中,网络系统或产品未正确过滤其中的特殊字符、命令等。攻击者可利用该漏洞执行非法操作系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/cpandya2909/CVE-2020-15778 | POC Details |
| 2 | Exploit for CVE-2020-15778(OpenSSH vul) | https://github.com/Neko-chanQwQ/CVE-2020-15778-Exploit | POC Details |
| 3 | None | https://github.com/Evan-Zhangyf/CVE-2020-15778 | POC Details |
| 4 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/OpenSSH%20%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%20CVE-2020-15778.md | POC Details |
| 5 | This script is a safe and simple tool that helps system users, students, and administrators check if their SCP (Secure Copy) client is vulnerable to CVE-2020-15778, a command injection vulnerability in OpenSSH SCP (versions ≤ 8.3p1). | https://github.com/drackyjr/CVE-2020-15778-SCP-Command-Injection-Check | POC Details |
| 6 | None | https://github.com/yifanzhg/CVE-2020-15778 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-15945 | Lua 安全漏洞 | |
| CVE-2020-15924 | Mida Solutions eFramework SQL注入漏洞 | |
| CVE-2020-15923 | Mida Solutions eFramework 路径遍历漏洞 | |
| CVE-2020-15922 | Mida Solutions eFramework 操作系统命令注入漏洞 | |
| CVE-2020-15921 | Mida Solutions eFramework 授权问题漏洞 | |
| CVE-2020-15920 | Mida Solutions eFramework 操作系统命令注入漏洞 | |
| CVE-2020-15919 | Mida Solutions eFramework 跨站脚本漏洞 | |
| CVE-2020-15918 | Mida Solutions eFramework 跨站脚本漏洞 | |
| CVE-2020-15860 | Parallels Remote Application Server 安全漏洞 | |
| CVE-2020-15932 | Overwolf 后置链接漏洞 | |
| CVE-2020-10614 | OSIsoft PI Vision 跨站脚本漏洞 | |
| CVE-2020-8207 | Citrix Systems Workspace App 授权问题漏洞 | |
| CVE-2020-8175 | jpeg-js 资源管理错误漏洞 | |
| CVE-2020-8174 | Joyent Node.js 数字错误漏洞 | |
| CVE-2020-12812 | Fortinet FortiOS SSL VPN 授权问题漏洞 | |
| CVE-2020-10610 | 多款OSIsoft产品代码问题漏洞 | |
| CVE-2020-10608 | 多款OSIsoft产品数据伪造问题漏洞 | |
| CVE-2020-10606 | 多款OSIsoft产品安全漏洞 | |
| CVE-2020-10602 | OSIsoft PI Data Archive 代码问题漏洞 | |
| CVE-2020-10604 | OSIsoft PI Data Archive 安全漏洞 |
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.