Dataprobe iBoot-PDU是美国Dataprobe公司的一种可通过 Web 访问的受管 PDU 独立控制的插座。 Dataprobe iBoot-PDU FW存在代码问题漏洞,该漏洞源于攻击者可以通过精心制作的PHP脚本(使用来自HTTP请求的参数)来创建能够更改主机参数的URL。HTTP中更改的主机参数可以指向另一个主机,该主机将向更改的主机参数中指定的主机或IP发送请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Dataprobe | iBoot-PDU FW | 0 ~ 1.42.06162022 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-3183 | 9.8 CRITICAL | Dataprobe iBoot-PDU 操作系统命令注入漏洞 |
| CVE-2022-3184 | 9.8 CRITICAL | Dataprobe iBoot-PDU 路径遍历漏洞 |
| CVE-2022-3186 | 8.6 HIGH | Dataprobe iBoot-PDU 安全漏洞 |
| CVE-2022-3185 | 5.3 MEDIUM | Dataprobe iBoot-PDU 信息泄露漏洞 |
| CVE-2022-3187 | 5.3 MEDIUM | Dataprobe iBoot-PDU 授权问题漏洞 |
| CVE-2022-3188 | 5.3 MEDIUM | Dataprobe iBoot-PDU 访问控制错误漏洞 |
No comments yet