Git是一套免费、开源的分布式版本控制系统。 Git 1.7.3版本存在授权问题漏洞,该漏洞源于可以为意外资源使用密码。为了进行利用,用户必须执行一次git pull操作,解密密码,并使用密码登录到远程服务。如果攻击者可利用该漏洞控制中央Git服务器或其他成员的一个机器,并控制服务已经在密码存储之一,他们可以重命名一个Git仓库密码文件的其他东西:通过不正确的验证文件的内容匹配的文件名,那么用户可能会骗解密和发送错误的密码
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-7787 | 8.2 HIGH | Improper Authentication |
| CVE-2020-7776 | 7.1 HIGH | Cross-site Scripting (XSS) |
| CVE-2020-29259 | SourceCodester Online Examination System 跨站脚本漏洞 | |
| CVE-2020-16587 | Industrial Light And Magic OpenEXR 缓冲区错误漏洞 | |
| CVE-2020-29258 | SourceCodester Online Examination System 跨站脚本漏洞 | |
| CVE-2020-29257 | SourceCodester Online Examination System 跨站脚本漏洞 | |
| CVE-2020-16600 | Artifex Software MuPDF 资源管理错误漏洞 | |
| CVE-2020-16599 | GNU Binutils 代码问题漏洞 | |
| CVE-2020-16593 | GNU Binutils 代码问题漏洞 | |
| CVE-2020-16592 | GNU Binutils 资源管理错误漏洞 | |
| CVE-2020-16591 | GNU Binutils 缓冲区错误漏洞 | |
| CVE-2020-16590 | GNU Binutils 资源管理错误漏洞 | |
| CVE-2020-25499 | TotoLink A3002RU 命令注入漏洞 | |
| CVE-2020-29660 | Linux kernel 资源管理错误漏洞 | |
| CVE-2020-29661 | Linux kernel 资源管理错误漏洞 | |
| CVE-2020-29659 | Flexense DupScout Enterprise 缓冲区错误漏洞 | |
| CVE-2020-25199 | Wecon Technologies LeviStudioU 缓冲区错误漏洞 | |
| CVE-2020-23520 | Imcat 代码问题漏洞 | |
| CVE-2020-29657 | JerryScript 缓冲区错误漏洞 | |
| CVE-2020-29655 | ASUS RT-AC88U 注入漏洞 |
Showing top 20 of 27 CVEs. View all on vendor page → →
No comments yet