Zoho Corporation Zoho ManageEngine Network Configuration Manager是美国Zoho Corporation公司的一种多供应商网络变更、配置和合规性管理 (Nccm) 解决方案。用于自动化并全面控制设备配置管理的整个生命周期。 Zoho ManageEngine Network Configuration Manager 存在命令注入漏洞,该漏洞源于产品的Ping功能未对用户输入数据进行有效过滤。攻击者可通过该漏洞执行系统命令。以下产品及版本受到影
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-43284 | Victure WR1200信任管理问题漏洞 | |
| CVE-2021-40101 | PortlandLabs Concrete CMS 安全漏洞 | |
| CVE-2021-42564 | Cryptshare Ag Cryptshare 输入验证错误漏洞 | |
| CVE-2021-31787 | Actions ATS2815 输入验证错误漏洞 | |
| CVE-2021-42099 | Zoho ManageEngine M365 Manager Plus 4421 代码问题漏洞 | |
| CVE-2021-22095 | Spring AMQP 代码问题漏洞 | |
| CVE-2021-43296 | Zoho ManageEngine SupportCenter Plus 代码问题漏洞 | |
| CVE-2021-43295 | Zoho ManageEngine SupportCenter Plus 跨站脚本漏洞 | |
| CVE-2021-43294 | Zoho ManageEngine SupportCenter Plus 跨站脚本漏洞 | |
| CVE-2021-41677 | Open Solutions For Education openSIS SQL注入漏洞 | |
| CVE-2021-43283 | Victure WR1200 操作系统命令注入漏洞 | |
| CVE-2021-43282 | Victure WR1200 信任管理问题漏洞 | |
| CVE-2021-44230 | PortSwigger Burp Suite 访问控制错误漏洞 | |
| CVE-2021-43202 | Jetbrains JetBrains TeamCity 访问控制错误漏洞 | |
| CVE-2021-43998 | HashiCorp Vault 安全漏洞 | |
| CVE-2021-41679 | Open Solutions For Education openSIS SQL注入漏洞 | |
| CVE-2021-41678 | Open Solutions For Education openSIS SQL注入漏洞 |
No comments yet