OS4Ed OpenSIS是OS4Ed的商业级、安全、可扩展和直观的学生信息系统、学校管理软件。具有在一个安装中运行单个或多个机构的所有功能。基于 Web,php 代码,MySQL 数据库。 OS4Ed OpenSIS Community存在路径遍历漏洞,该漏洞源于OS4Ed OpenSIS Community 8.0 容易受到 Modules.php(modname 参数)中的本地文件包含漏洞的影响,只要应用程序有权访问该文件,该漏洞就可以从服务器的文件系统中泄露任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-40651.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-23446 | 7.5 HIGH | Regular Expression Denial of Service (ReDoS) |
| CVE-2021-41573 | 7.5 HIGH | Hitachi Content Platform Anywhere (HCP-AW) 信息泄露漏洞 |
| CVE-2021-35943 | Couchbase Server 授权问题漏洞 | |
| CVE-2021-22947 | Migration Toolkit For Containers 数据伪造问题漏洞 | |
| CVE-2021-22946 | libcurl 安全漏洞 | |
| CVE-2021-33923 | Confluent Ansible 安全漏洞 | |
| CVE-2021-33924 | Confluent Ansible 安全漏洞 | |
| CVE-2021-41732 | Zeek 环境问题漏洞 | |
| CVE-2021-41764 | Streama 跨站请求伪造漏洞 | |
| CVE-2021-35945 | Couchbase Server 缓冲区错误漏洞 | |
| CVE-2021-41826 | PlaceOs Authentication Service 输入验证错误漏洞 | |
| CVE-2021-35944 | Couchbase Server 缓冲区错误漏洞 | |
| CVE-2021-3653 | KVM 权限许可和访问控制问题漏洞 | |
| CVE-2021-41795 | Apple Safari 安全漏洞 | |
| CVE-2020-20128 | LaraCms 信息泄露漏洞 | |
| CVE-2020-20129 | LaraCms 跨站脚本漏洞 | |
| CVE-2020-20131 | LaraCms 跨站脚本漏洞 | |
| CVE-2020-20781 | UCMS 跨站脚本漏洞 | |
| CVE-2021-41821 | Wazuh 数字错误漏洞 | |
| CVE-2021-41824 | Pixel&tonic Craft CMS 代码注入漏洞 |
No comments yet