OpenSSL是Openssl团队的一个开源的能够实现安全套接层(SSLv2/v3)和安全传输层(TLSv1)协议的通用加密库。该产品支持多种加密算法,包括对称密码、哈希算法、安全散列算法等。 OpenSSL 存在操作系统命令注入漏洞,该漏洞源于c_rehash 脚本未正确清理 shell 元字符导致命令注入。攻击者利用该漏洞执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2022-1292 | https://github.com/li8u99/CVE-2022-1292 | POC Details |
| 2 | CVE-2022-1292 OpenSSL c_rehash Vulnerability - POC | https://github.com/alcaparra/CVE-2022-1292 | POC Details |
| 3 | CVE-2022-1292 OpenSSL c_rehash Vulnerability | https://github.com/rama291041610/CVE-2022-1292 | POC Details |
| 4 | OpenSSL | https://github.com/greek0x0/CVE-2022-1292 | POC Details |
| 5 | Automation to validate the impact of the vulnerability CVE-2022-1292 on a specific system. | https://github.com/und3sc0n0c1d0/CVE-2022-1292 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-1343 | OCSP_basic_verify may incorrectly verify the response signing certificate | |
| CVE-2022-1434 | Incorrect MAC key used in the RC4-MD5 ciphersuite | |
| CVE-2022-1473 | Resource leakage when decoding certificates and keys |
No comments yet