mongo-express是一款用于交互式管理MongoDB数据库的、基于Web的轻量级管理界面。 mongo-express before 1.0.0 存在安全漏洞,该漏洞源于以一种不安全的方式实现了某些高级语法的支持。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Mongo-Express before 1.0.0 is susceptible to remote code execution because it uses safer-eval to validate user supplied javascript. Unfortunately safer-eval sandboxing capabilities are easily bypassed leading to remote code execution in the context of the node server. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-24391.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-23363 | 6.3 MEDIUM | Arbitrary Command Injection |
| CVE-2021-25157 | Aruba Access Points 输入验证错误漏洞 | |
| CVE-2020-20545 | Zhiyuan G6 Government Collaboration System 跨站脚本漏洞 | |
| CVE-2018-1110 | CZ.NIC knot-resolver 输入验证错误漏洞 | |
| CVE-2018-1109 | Npm Braces 资源管理错误漏洞 | |
| CVE-2018-1107 | Npm is-my-json-valid 资源管理错误漏洞 | |
| CVE-2019-5319 | Aruba Access Points 安全漏洞 | |
| CVE-2021-25161 | Aruba Instant Access Point 跨站脚本漏洞 | |
| CVE-2021-25162 | Aruba Instant Access Point 命令注入漏洞 | |
| CVE-2021-25160 | Aruba Instant Access Point 输入验证错误漏洞 | |
| CVE-2021-25159 | Aruba Instant Access Point 输入验证错误漏洞 | |
| CVE-2020-19639 | INSMA Wifi Mini Spy 1080P HD Security IP Camera 跨站请求伪造漏洞 | |
| CVE-2021-25158 | Aruba Access Points 竞争条件问题漏洞 | |
| CVE-2021-25156 | Aruba Access Points 输入验证错误漏洞 | |
| CVE-2021-25155 | Aruba Access Points 输入验证错误漏洞 | |
| CVE-2021-25150 | Aruba Access Points 命令注入漏洞 | |
| CVE-2021-25146 | Aruba Access Points 命令注入漏洞 | |
| CVE-2021-3474 | LIM OpenEXR 输入验证错误漏洞 | |
| CVE-2021-3475 | OpenEXR 输入验证错误漏洞 | |
| CVE-2021-3476 | LIM OpenEXR 输入验证错误漏洞 |
Showing top 20 of 39 CVEs. View all on vendor page → →
No comments yet