Vmware Workspace One Access是美国Vmware公司的将用户身份与设备和网络信息等因素结合起来,为 Workspace One 交付的应用程序制定智能驱动的条件访问决策。 VMware 多款产品存在代码注入漏洞,该漏洞源于不正确的输入验证。远程攻击者利用该漏洞发送特制的HTTP请求并执行服务器端模板注入。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| - | VMware Workspace ONE Access and Identity Manager | Access 21.08.0.1, 21.08.0.0, 20.10.0.1, 20.10.0.0. Identity Manager 3.3.6, 3.3.5, 3.3.4, 3.3.3. | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | 提供单个或批量URL扫描是否存在CVE-2022-22954功能 | https://github.com/axingde/CVE-2022-22954-POC | POC详情 |
| 2 | POC for VMWARE CVE-2022-22954 | https://github.com/sherlocksecurity/VMware-CVE-2022-22954 | POC详情 |
| 3 | CVE-2022-22954 is a server-side template injection vulnerability in the VMware Workspace ONE Access and Identity Manager | https://github.com/Vulnmachines/VMWare_CVE-2022-22954 | POC详情 |
| 4 | None | https://github.com/aniqfakhrul/CVE-2022-22954 | POC详情 |
| 5 | 提供批量扫描URL以及执行命令功能。Workspace ONE Access 模板注入漏洞,可执行任意代码 | https://github.com/jax7sec/CVE-2022-22954 | POC详情 |
| 6 | CVE-2022-22954-VMware-RCE批量检测POC | https://github.com/bb33bb/CVE-2022-22954-VMware-RCE | POC详情 |
| 7 | None | https://github.com/lucksec/VMware-CVE-2022-22954 | POC详情 |
| 8 | None | https://github.com/mumu2020629/-CVE-2022-22954-scanner | POC详情 |
| 9 | CVE-2022-22954 Açığı test etme | https://github.com/MSeymenD/CVE-2022-22954-Testi | POC详情 |
| 10 | None | https://github.com/corelight/cve-2022-22954 | POC详情 |
| 11 | PoC for CVE-2022-22954 - VMware Workspace ONE Access Freemarker Server-Side Template Injection | https://github.com/DrorDvash/CVE-2022-22954_VMware_PoC | POC详情 |
| 12 | VMware Workspace ONE Access远程代码执行漏洞 / Code By:Jun_sheng | https://github.com/Jun-5heng/CVE-2022-22954 | POC详情 |
| 13 | VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual. | https://github.com/tunelko/CVE-2022-22954-PoC | POC详情 |
| 14 | CVE-2022-22954 VMware Workspace ONE Access freemarker SSTI 漏洞 命令执行、批量检测脚本、文件写入 | https://github.com/bewhale/CVE-2022-22954 | POC详情 |
| 15 | Proof of Concept for exploiting VMware CVE-2022-22954 | https://github.com/tyleraharrison/VMware-CVE-2022-22954-Command-Injector | POC详情 |
| 16 | CVE-2022-22954 VMware Workspace ONE Access free marker SSTI | https://github.com/MLX15/CVE-2022-22954 | POC详情 |
| 17 | None | https://github.com/mhurts/CVE-2022-22954-POC | POC详情 |
| 18 | CVE-2022-22954 analyst | https://github.com/nguyenv1nK/CVE-2022-22954 | POC详情 |
| 19 | Python script to exploit CVE-2022-22954 and then exploit CVE-2022-22960 | https://github.com/Chocapikk/CVE-2022-22954 | POC详情 |
| 20 | Python script to exploit CVE-2022-22954 and then exploit CVE-2022-22960 | https://github.com/secfb/CVE-2022-22954 | POC详情 |
| 21 | None | https://github.com/orwagodfather/CVE-2022-22954 | POC详情 |
| 22 | VMware Workspace ONE Access and Identity Manager RCE via SSTI. CVE-2022-22954 - PoC SSTI * exploit+payload+shodan (ну набором) | https://github.com/b4dboy17/CVE-2022-22954 | POC详情 |
| 23 | Practising technical writing with researching CVE-2022-22954 VMware Workspace ONE Access RCE vulnerability. | https://github.com/arzuozkan/CVE-2022-22954 | POC详情 |
| 24 | I'm trying | https://github.com/1SeaMy/CVE-2022-22954 | POC详情 |
| 25 | None | https://github.com/amit-pathak009/CVE-2022-22954 | POC详情 |
| 26 | None | https://github.com/amit-pathak009/CVE-2022-22954-PoC | POC详情 |
| 27 | 一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密连接 | https://github.com/Schira4396/VcenterKiller | POC详情 |
| 28 | None | https://github.com/lolminerxmrig/CVE-2022-22954_ | POC详情 |
| 29 | None | https://github.com/Jhonsonwannaa/CVE-2022-22954 | POC详情 |
| 30 | Proof of Concept for exploiting VMware CVE-2022-22954 | https://github.com/emilyastranova/VMware-CVE-2022-22954-Command-Injector | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2021-32162 | Webmin 跨站请求伪造漏洞 | |
| CVE-2021-37291 | KevinLAB Building Energy Management System SQL注入漏洞 | |
| CVE-2021-40219 | Bolt CMS 代码注入漏洞 | |
| CVE-2022-27111 | Jfinal CMS跨站脚本漏洞 | |
| CVE-2022-27156 | Daylight Studio Fuel CMS跨站脚本漏洞 | |
| CVE-2022-27115 | elFinder 代码问题漏洞 | |
| CVE-2022-27088 | Ivanti DSM Remote 及 代码问题漏洞 | |
| CVE-2022-27089 | Fujitsu PlugFree Network 代码问题漏洞 | |
| CVE-2022-27041 | openSIS SQL注入漏洞 | |
| CVE-2021-37293 | KevinLAB Building Energy Management System 路径遍历漏洞 | |
| CVE-2021-32161 | Webmin 跨站脚本漏洞 | |
| CVE-2021-32160 | Webmin 跨站脚本漏洞 | |
| CVE-2021-32159 | Webmin 跨站请求伪造漏洞 | |
| CVE-2021-32158 | Webmin 跨站脚本漏洞 | |
| CVE-2021-32157 | Webmin 跨站脚本漏洞 | |
| CVE-2021-32156 | Webmin 跨站请求伪造漏洞 | |
| CVE-2022-28893 | Linux kernel 资源管理错误漏洞 | |
| CVE-2022-25794 | Autodesk FBX Review 缓冲区错误漏洞 | |
| CVE-2022-25790 | Autodesk AutoCAD 缓冲区错误漏洞 | |
| CVE-2021-4047 | Red Hat OpenShift 输入验证错误漏洞 |
显示前 20 条,共 37 条。 查看全部 → →
暂无评论