Sangfor Next-Gen Application Firewall(Sangfor NGAF)是中国深信服(Sangfor)公司的一款应用防火墙。 Sangfor Next-Gen Application Firewall NGAF8.0.17版本存在安全漏洞,该漏洞源于允许经过身份验证的攻击者使用svpn_html/loadfile.php端点读取任意系统文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Sangfor | Net-Gen Application Firewall | 8.0.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-30806 | 9.8 CRITICAL | Sangfor Next-Gen Application Firewall PHPSESSID Command Injection |
| CVE-2023-30805 | 9.8 CRITICAL | Sangfor Next-Gen Application Firewall Login Un Param Command Injection |
| CVE-2023-30803 | 9.8 CRITICAL | Sangfor Next-Gen Application Firewall Authentication Bypass |
| CVE-2023-30802 | 5.3 MEDIUM | Sangfor Next-Gen Application Firewall Source Code Disclosure |
No comments yet