Liftoff GateOne是Liftoff个人开发者的一个基于HTML5的可提供终端、ssh client功能的工具软件。 GateOne 1.1 存在路径遍历漏洞,该漏洞允许/downloads/路径遍历,任意文件下载,无需通过下载验证。因为os.path.join是滥用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | GateOne 1.1 allows arbitrary file retrieval without authentication via /downloads/.. local file inclusion because os.path.join is incorrectly used. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-35736.yaml | POC Details |
| 2 | None | https://github.com/chaitin/xray-plugins/blob/main/poc/manual/gateone-cve-2020-35736.yml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-29156 | WordPress plugin WooCommerce 权限许可和访问控制问题漏洞 | |
| CVE-2020-29250 | Cxuucms 跨站脚本漏洞 | |
| CVE-2020-29249 | Cxuucms 跨站脚本漏洞 | |
| CVE-2020-29299 | Zyxel ZLD和Zyxel SD-OS 命令注入漏洞 | |
| CVE-2020-29204 | XXL-JOB 跨站脚本漏洞 | |
| CVE-2020-35729 | KLog Server 操作系统命令注入漏洞 | |
| CVE-2020-35728 | FasterXML jackson-databind 代码问题漏洞 | |
| CVE-2020-35448 | GNU Binutils 缓冲区错误漏洞 | |
| CVE-2020-8290 | Backblaze 权限许可和访问控制问题漏洞 | |
| CVE-2020-8289 | Backblaze 信任管理问题漏洞 | |
| CVE-2020-35678 | Python 输入验证错误漏洞 |
No comments yet