洪湖尔创网联信息技术 EARCLINK ESPCMS是中国洪湖尔创网联信息技术公司的一套企业建站系统。 EARCLINK ESPCMS-P8的espcms_web/Search.php组件存在SQL注入漏洞,攻击者可利用该漏洞访问敏感的数据库信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| envoyproxy | envoy | >= 1.19.0, < 1.19.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-32777 | 8.6 HIGH | Incorrect concatenation of multiple value request headers in ext-authz extension |
| CVE-2021-32779 | 8.6 HIGH | Incorrectly handling of URI '#fragment' element as part of the path element |
| CVE-2021-32780 | 8.6 HIGH | Incorrect handling of H/2 GOAWAY followed by SETTINGS frames |
| CVE-2021-32781 | 8.6 HIGH | Continued processing of requests after locally generated response |
No comments yet