echo是LabStack LLC开源的一个高性能、极简的 Go web 框架。 LabStack LLC echo v4.8.0 版本存在安全漏洞,该漏洞源于 Static Handler 组件存在开放重定向问题,可能导致服务器端请求伪造(SSRF)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Labstack Echo 4.8.0 contains an open redirect vulnerability via the Static Handler component. An attacker can leverage this vulnerability to cause server-side request forgery, making it possible to obtain sensitive information, modify data, and/or execute unauthorized operations. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-40083.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-3287 | fwupd 安全漏洞 | |
| CVE-2022-3193 | ovirt-engine 跨站脚本漏洞 | |
| CVE-2021-41434 | Expense Management System 跨站脚本漏洞 | |
| CVE-2022-38934 | ToaruOS 缓冲区错误漏洞 | |
| CVE-2022-36448 | Insyde InsydeH2O 输入验证错误漏洞 | |
| CVE-2022-40942 | Tenda TX3 缓冲区错误漏洞 | |
| CVE-2022-40912 | ETAP Lighting International ETAP Safety Manager 跨站脚本漏洞 | |
| CVE-2022-40082 | Hertz 路径遍历漏洞 | |
| CVE-2022-40486 | TP-LINK AX10 代码注入漏洞 | |
| CVE-2022-30935 | b2evolution 安全特征问题漏洞 | |
| CVE-2022-1270 | GraphicsMagick 缓冲区错误漏洞 | |
| CVE-2022-40929 | XXL-JOB 操作系统命令注入漏洞 |
No comments yet