WSO2 API Manager等都是美国WSO2公司的产品。WSO2 API Manager是一套API生命周期管理解决方案。WSO2 Dashboard Server是一款仪表板服务器。WSO2 Identity Server(IS)是一款身份认证服务器。 WSO2 多个产品存在安全漏洞,该漏洞源于输出编码不正确。攻击者利用此漏洞可以使浏览器重定向到恶意网站,在网页 UI 中进行更改,从浏览器中检索信息或以其他方式造成伤害。以下产品和版本受到影响:WSO2 API Manager : 2.2.0,2.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Proof of concept exploit for CVE-2022-29548: A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0. | https://github.com/cxosmo/CVE-2022-29548 | POC Details |
| 2 | WSO2 contains a reflected cross-site scripting vulnerability in the Management Console of API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-29548.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-28743 | 9.1 CRITICAL | Foscam R2C IP 安全漏洞 |
| CVE-2022-28007 | Attendance and Payroll System SQL注入漏洞 | |
| CVE-2022-28017 | Attendance and Payroll System SQL注入漏洞 | |
| CVE-2022-28022 | Purchase Order Management System SQL注入漏洞 | |
| CVE-2022-28021 | Purchase Order Management System 代码问题漏洞 | |
| CVE-2022-28020 | Attendance and Payroll System SQL注入漏洞 | |
| CVE-2022-28023 | Purchase Order Management System SQL注入漏洞 | |
| CVE-2022-28025 | Student Grading System SQL注入漏洞 | |
| CVE-2022-28024 | Student Grading System SQL注入漏洞 | |
| CVE-2022-28026 | Student Grading System SQL注入漏洞 | |
| CVE-2022-28028 | Simple Real Estate Portal System SQL注入漏洞 | |
| CVE-2022-28030 | Simple Real Estate Portal System SQL注入漏洞 | |
| CVE-2022-28029 | Simple Real Estate Portal System SQL注入漏洞 | |
| CVE-2022-28410 | Simple Real Estate Portal System SQL注入漏洞 | |
| CVE-2022-28411 | Simple Real Estate Portal System SQL注入漏洞 | |
| CVE-2022-28412 | Car Driving School Management System SQL注入漏洞 | |
| CVE-2022-28414 | Home Owners Collection Management System SQL注入漏洞 | |
| CVE-2022-28413 | Car Driving School Management System SQL注入漏洞 | |
| CVE-2022-28416 | Home Owners Collection Management System SQL注入漏洞 | |
| CVE-2022-28415 | Home Owners Collection Management System SQL注入漏洞 |
Showing top 20 of 74 CVEs. View all on vendor page → →
No comments yet