ZEND Zend Framework是美国ZEND公司的一套开源的PHP开发框架,它主要用于开发Web程序和服务。Laminas Project laminas-http是Laminas Project的一个 HTTP 消息和标头抽象,以及 HTTP 客户端实现。 Laminas Project laminas-http 2.14.2 之前版本和Zend Framework 3.0.0版本存在代码问题漏洞,该漏洞源于有一个反序列化漏洞,攻击者可利用该漏洞远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | ZendFramework_CVE-2021-3007 PoC | https://github.com/Vulnmachines/ZF3_CVE-2021-3007 | POC Details |
| 2 | None | https://github.com/yunus-a1i/CVE-2021-3007-docker-poc | POC Details |
| 3 | CVE-2021-3007 Vulnerable Test Environment - Laminas/Zend Framework Deserialization RCE | https://github.com/KrE80r/cve-2021-3007-vulnerable | POC Details |
| 4 | Laminas Project laminas-http < 2.14.2 and Zend Framework 3.0.0 contain a deserialization vulnerability caused by __destruct method in Zend\\Http\\Response\\Stream, letting attackers control content lead to remote code execution, exploit requires attacker-controlled serialized data. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3007.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-36155 | 10.0 CRITICAL | WordPress 安全漏洞 |
| CVE-2020-36157 | 10.0 CRITICAL | WordPress 输入验证错误漏洞 |
| CVE-2020-36156 | 9.9 CRITICAL | Ultimate Member plugin before for WordPress 安全漏洞 |
| CVE-2020-28464 | 9.8 CRITICAL | Remote Code Execution (RCE) |
| CVE-2020-7771 | 7.5 HIGH | Prototype Pollution |
| CVE-2020-35495 | GNU Binutils 代码问题漏洞 | |
| CVE-2021-3014 | Mikrotik MikroTik RouterOS 跨站脚本漏洞 | |
| CVE-2020-35219 | ASUS DSL-N17U 授权问题漏洞 | |
| CVE-2020-24386 | Dovecot 安全漏洞 | |
| CVE-2020-25275 | Dovecot 输入验证错误漏洞 | |
| CVE-2020-36154 | Pearson Vue VTS Installer 安全漏洞 | |
| CVE-2020-36112 | Projectworlds Online Book Store Project In Php SQL注入漏洞 | |
| CVE-2020-35507 | GNU Binutils 代码问题漏洞 | |
| CVE-2020-35496 | GNU Binutils 代码问题漏洞 | |
| CVE-2019-25013 | GNU C Library 缓冲区错误漏洞 | |
| CVE-2020-35494 | GNU Binutils 安全漏洞 | |
| CVE-2020-35493 | GNU Binutils 输入验证错误漏洞 | |
| CVE-2020-22550 | VFM Veno File Manager 路径遍历漏洞 | |
| CVE-2019-16960 | Solarwinds WebHelpDesk 跨站脚本漏洞 | |
| CVE-2019-16956 | SolarWinds Web Help Desk 跨站脚本漏洞 |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet