ThinVNC是一款基于HTML5和AJAX的远程桌面实现。 ThinVNC 1.0b1版本存在安全漏洞,该漏洞源于应用缺少身份验证。未经身份验证的攻击者通过“http://thin-vnc:8080/cmd?cmd=connect”绕过身份验证过程,无需任何身份验证即可获得有效的 SID,还可以通过向服务器发送键盘或鼠标事件利用该漏洞实现服务器上的代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | ThinVNC | 1.0b1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via a specific command, potentially leading to unauthorized access and code execution. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-25226.yaml | POC Details |
| 2 | ThinVNC 1.0b1 - Authentication Bypass to RCE | https://github.com/krill-x7/CVE-2022-25226 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-29464 | 9.8 CRITICAL | WSO2 API Manager 路径遍历漏洞 |
| CVE-2022-27525 | Autodesk AutoCAD 缓冲区错误漏洞 | |
| CVE-2022-29457 | ZOHO ManageEngine ADSelfService Plus 安全漏洞 | |
| CVE-2011-4917 | Linux kernel 安全漏洞 | |
| CVE-2021-42778 | OpenSC 资源管理错误漏洞 | |
| CVE-2011-1762 | Wordpress 安全漏洞 | |
| CVE-2021-3681 | Ansible Galaxy Collections 安全漏洞 | |
| CVE-2021-3503 | Red Hat Wildfly 安全漏洞 | |
| CVE-2021-3624 | dcraw 输入验证错误漏洞 | |
| CVE-2022-1341 | bwm-ng 代码问题漏洞 | |
| CVE-2022-27652 | cri-o 安全漏洞 | |
| CVE-2022-27530 | Autodesk AutoCAD 缓冲区错误漏洞 | |
| CVE-2022-27529 | Autodesk AutoCAD 缓冲区错误漏洞 | |
| CVE-2022-27526 | Autodesk Design Review 缓冲区错误漏洞 | |
| CVE-2021-3652 | 389-ds-base 安全漏洞 | |
| CVE-2021-46122 | TP-LINK TL-WR840N 安全漏洞 | |
| CVE-2022-26665 | Tyler Technologies Tyler Odyssey 安全漏洞 | |
| CVE-2022-26631 | ResearchGate Automatic Question Paper Generator System SQL注入漏洞 | |
| CVE-2022-28810 | ZOHO ManageEngine ADSelfService Plus 信任管理问题漏洞 | |
| CVE-2022-27908 | ZOHO ManageEngine OpManager SQL注入漏洞 |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet