Sas Institute Sas/IntrNet是美国Sas Institute公司的一套 Cgi 和 Java 工具。用于创建和部署支持 Web 的报告和应用程序。 Sas Institute SAS/Intrnet存在安全漏洞,该漏洞源于网络系统或产品的代码开发过程中存在设计或实现不当的问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | SAS/Internet 9.4 build 1520 and earlier allows local file inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to access the sample.webcsf1.sas program, which contains user-controlled macro variables that are passed to the DS2CSF macro. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41569.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-23433 | 5.9 MEDIUM | Prototype Pollution |
| CVE-2021-37592 | Suricata 缓冲区错误漏洞 | |
| CVE-2021-29323 | Moddable SDK 缓冲区错误漏洞 | |
| CVE-2021-29324 | Moddable SDK 缓冲区错误漏洞 | |
| CVE-2021-22028 | Greenplum Database 路径遍历漏洞 | |
| CVE-2021-3962 | ImageMagick 资源管理错误漏洞 | |
| CVE-2021-22030 | Greenplum Database 日志信息泄露漏洞 | |
| CVE-2021-22053 | VMware Spring Cloud Netflix 代码注入漏洞 | |
| CVE-2021-33850 | WordPress 跨站脚本漏洞 | |
| CVE-2021-29325 | Moddable SDK 缓冲区错误漏洞 | |
| CVE-2021-41435 | ASUS routers 安全漏洞 | |
| CVE-2021-41436 | ASUS routers 环境问题漏洞 | |
| CVE-2021-44033 | Ionic Identity Vault 安全漏洞 | |
| CVE-2021-44025 | Roundcube Webmail 跨站脚本漏洞 | |
| CVE-2021-44026 | Roundcube Webmail SQL注入漏洞 | |
| CVE-2021-21898 | LibreCAD 缓冲区错误漏洞 | |
| CVE-2021-21899 | LibreCAD 缓冲区错误漏洞 | |
| CVE-2021-21900 | LibreCAD 资源管理错误漏洞 | |
| CVE-2021-29326 | Moddable SDK 缓冲区错误漏洞 | |
| CVE-2021-29327 | Moddable SDK 缓冲区错误漏洞 |
Showing top 20 of 35 CVEs. View all on vendor page → →
No comments yet