WSO2 API Manager是美国WSO2公司的一套API生命周期管理解决方案。 WSO2 API Manager 3.1.0 存在跨站脚本漏洞,攻击者可利用该漏洞可以通过窃取cookie来劫持登录用户的会话,在保持访问权限的同时更改登录用户的密码,使受害者的会话无效。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-7746 | 7.5 HIGH | Prototype Pollution |
| CVE-2020-5931 | F5 BIG-IP 安全漏洞 | |
| CVE-2020-14323 | Samba 代码问题漏洞 | |
| CVE-2020-25516 | WSO2 Enterprise Integrator 跨站脚本漏洞 | |
| CVE-2020-5938 | F5 BIG-IP 加密问题漏洞 | |
| CVE-2020-5937 | F5 BIG-IP APM 安全漏洞 | |
| CVE-2020-21266 | Broadleaf Commerce 跨站脚本漏洞 | |
| CVE-2020-27993 | Hrsale 路径遍历漏洞 | |
| CVE-2020-5935 | F5 BIG-IP 安全漏洞 | |
| CVE-2020-5933 | F5 BIG-IP 安全漏洞 | |
| CVE-2020-5932 | F5 BIG-IP ASM 跨站脚本漏洞 | |
| CVE-2020-27887 | EyesOfNetwork 操作系统命令注入漏洞 | |
| CVE-2020-5934 | F5 BIG-IP APM 安全漏洞 | |
| CVE-2020-5936 | F5 BIG-IP 资源管理错误漏洞 | |
| CVE-2020-25780 | Commvault CommCell 路径遍历漏洞 | |
| CVE-2020-27744 | Western Digital My Cloud 操作系统命令注入漏洞 | |
| CVE-2020-27995 | ZOHO ManageEngine Applications Manager SQL注入漏洞 | |
| CVE-2020-27996 | Smartstore SmartStoreNET 安全漏洞 | |
| CVE-2020-27998 | FastReports fastreport 加密问题漏洞 | |
| CVE-2020-27747 | Click Studios Passwordstate 安全漏洞 |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet