Amazon AWS是美国亚马逊(Amazon)公司的一款云计算平台,向个人、企业和政府提供一系列包括信息技术基础架构和应用的服务,如存储、数据库、计算、机器学习等等。 Amazon AWS Apache log4j-cve-2021-44228-hotpatch-1.3.5 之前版本存在安全漏洞,该漏洞源于应用存在本地竞争条件问题。本地攻击者利用该漏洞可以通过运行自定义 java 进程来使 hotpatch 脚本以提升的权限执行二进制文件.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-25852 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-22138 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-21213 | 7.5 HIGH | Prototype Pollution |
| CVE-2022-25345 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-25856 | 7.5 HIGH | Directory Traversal |
| CVE-2022-25871 | 5.9 MEDIUM | Prototype Pollution |
| CVE-2022-25872 | 5.3 MEDIUM | Out-of-bounds Read |
| CVE-2019-12353 | ZZCMS SQL注入漏洞 | |
| CVE-2022-33912 | CheckMK Raw Edition 安全漏洞 | |
| CVE-2019-12354 | ZZCMS SQL注入漏洞 | |
| CVE-2019-12355 | ZZCMS SQL注入漏洞 | |
| CVE-2019-12356 | ZZCMS SQL注入漏洞 | |
| CVE-2019-12357 | ZZCMS SQL注入漏洞 | |
| CVE-2019-12358 | ZZCMS SQL注入漏洞 | |
| CVE-2019-12359 | ZZCMS SQL注入漏洞 | |
| CVE-2021-45026 | ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 跨站脚本漏洞 | |
| CVE-2021-45025 | ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 安全漏洞 | |
| CVE-2021-45024 | ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 代码问题漏洞 | |
| CVE-2022-31784 | Mitel MiVoice Business Express 安全漏洞 | |
| CVE-2022-32276 | Grafana 授权问题漏洞 |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet