CrushFTP是一款文件传输服务器。 CrushFTP 10.5.1之前版本存在安全漏洞,该漏洞源于对象属性的不当控制,攻击者利用该漏洞可以获得对Java属性的部分控制,可以在主机系统上任意文件读取和删除原语。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CrushFTP <= 10.5.1 Remote Code Execution. Researchers: Ryan Emmons, Evan Malamis | https://github.com/the-emmons/CVE-2023-43177 | POC Details |
| 2 | CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-43177.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-6188 | 4.7 MEDIUM | GetSimpleCMS theme-edit.php code injection |
| CVE-2023-48649 | 3.5 LOW | PortlandLabs Concrete CMS 跨站脚本漏洞 |
| CVE-2023-45387 | PrestaShop 安全漏洞 | |
| CVE-2023-48659 | MISP 安全漏洞 | |
| CVE-2023-48658 | MISP 安全漏洞 | |
| CVE-2023-48657 | MISP 安全漏洞 | |
| CVE-2023-48656 | MISP 安全漏洞 | |
| CVE-2023-48655 | MISP 安全漏洞 | |
| CVE-2023-48648 | PortlandLabs Concrete CMS 安全漏洞 | |
| CVE-2023-48185 | TerraMaster NAS安全漏洞 | |
| CVE-2023-48031 | OpenSupports 安全漏洞 | |
| CVE-2023-48029 | coreBOS 安全漏洞 | |
| CVE-2023-48028 | kodbox 安全漏洞 | |
| CVE-2023-48025 | Liblisp 安全漏洞 | |
| CVE-2023-48024 | Liblisp 安全漏洞 | |
| CVE-2023-46402 | git-urls 安全漏洞 | |
| CVE-2023-45382 | PrestaShop 路径遍历漏洞 | |
| CVE-2023-44796 | LimeSurvey 安全漏洞 | |
| CVE-2023-41102 | OpenNDS 安全漏洞 | |
| CVE-2023-41101 | OpenNDS 安全漏洞 |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet