ISPConfig是一套基于Linux的开源主机控制面板,它可通过Web控制面板管理多台服务器、开设网站、监控服务器运行状况等。 ISPConfig 3.2.11p1 之前版本存在安全漏洞,该漏洞源于如果启用了 admin_allow_langedit,管理员可以在语言文件编辑器中实现 PHP 代码注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2023-46818 IPSConfig Python exploit | https://github.com/bipbopbup/CVE-2023-46818-python-exploit | POC Details |
| 2 | An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-46818.yaml | POC Details |
| 3 | This is my own exploit for CVE-2023-46818 happy hacking! | https://github.com/blindma1den/CVE-2023-46818-Exploit | POC Details |
| 4 | CVE-2023-46818 Python3 Exploit for ISPConfig <= 3.2.11 (language_edit.php) PHP Code Injection Vulnerability | https://github.com/ajdumanhug/CVE-2023-46818 | POC Details |
| 5 | CVE-2023-46818 Python3 Exploit for Backdrop CMS <= 1.22.0 Authenticated Remote Command Execution (RCE) | https://github.com/ajdumanhug/CVE-2022-42092 | POC Details |
| 6 | CVE-2023-46818 - ISPConfig PHP Code Injection PoC Exploit (Bash) | https://github.com/rvizx/CVE-2023-46818 | POC Details |
| 7 | None | https://github.com/engranaabubakar/CVE-2023-46818 | POC Details |
| 8 | An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled. | https://github.com/hunntr/CVE-2023-46818 | POC Details |
| 9 | Metasploit Modules | https://github.com/SyFi/CVE-2023-46818 | POC Details |
| 10 | Python PoC for CVE-2023-46818 | https://github.com/vulnerk0/CVE-2023-46818 | POC Details |
| 11 | CVE-2023-46818 | PoC | ISPConfig 3.2.11p1 | https://github.com/zs1n/CVE-2023-46818 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-34057 | 7.8 HIGH | VMware Tools 安全漏洞 |
| CVE-2023-34059 | 7.4 HIGH | VMware Tools 安全漏洞 |
| CVE-2023-34058 | 7.1 HIGH | VMware Tools 安全漏洞 |
| CVE-2023-46393 | gougucms 安全漏洞 | |
| CVE-2023-46853 | Memcached 安全漏洞 | |
| CVE-2023-46852 | Memcached 安全漏洞 | |
| CVE-2023-46816 | SugarCRM 安全漏洞 | |
| CVE-2023-46815 | SugarCRM 安全漏洞 | |
| CVE-2023-46813 | Linux kernel 安全漏洞 | |
| CVE-2023-46587 | XnView Classic 安全漏洞 | |
| CVE-2023-46510 | ZIONCOM Technology A7000R 安全漏洞 | |
| CVE-2023-46490 | Cacti SQL注入漏洞 | |
| CVE-2023-46407 | FFmpeg 安全漏洞 | |
| CVE-2023-46509 | Contec SolarView Compact 安全漏洞 | |
| CVE-2023-35794 | Cassia Networks Access Controller 安全漏洞 | |
| CVE-2022-34834 | VERMEG Agile Reporter 安全漏洞 | |
| CVE-2022-34833 | VERMEG Agile Reporter 安全漏洞 | |
| CVE-2022-34832 | VERMEG Agile Reporter 安全漏洞 | |
| CVE-2023-46375 | Nature Easy Soft Network Technology ZenTao 跨站请求伪造漏洞 | |
| CVE-2023-46376 | Nature Easy Soft Network Technology ZenTao 信息泄露漏洞 |
Showing top 20 of 27 CVEs. View all on vendor page → →
No comments yet