PHP是一种在服务器端执行的脚本语言。Dataprobe iBoot-PDU是美国Dataprobe公司的一种可通过 Web 访问的受管 PDU 独立控制的插座。 Dataprobe iBoot-PDU FW存在授权问题漏洞,该漏洞源于某些PHP页面只有在与数据库建立有效连接时才会验证。但是,这些PHP页面并不验证用户的有效性。攻击者可以利用这种验证的缺陷来读取出口点的状态。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Dataprobe | iBoot-PDU FW | 0 ~ 1.42.06162022 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-3183 | 9.8 CRITICAL | Dataprobe iBoot-PDU 操作系统命令注入漏洞 |
| CVE-2022-3184 | 9.8 CRITICAL | Dataprobe iBoot-PDU 路径遍历漏洞 |
| CVE-2022-3186 | 8.6 HIGH | Dataprobe iBoot-PDU 安全漏洞 |
| CVE-2022-3185 | 5.3 MEDIUM | Dataprobe iBoot-PDU 信息泄露漏洞 |
| CVE-2022-3188 | 5.3 MEDIUM | Dataprobe iBoot-PDU 访问控制错误漏洞 |
| CVE-2022-3189 | 5.3 MEDIUM | Dataprobe iBoot-PDU 代码问题漏洞 |
No comments yet