1Panel是中国1panel社区的一个开源的Linux服务器运维管理面板。 1Panel 1.10.1-lts及之前版本存在命令注入漏洞,该漏洞源于/api/v1/toolbox/device/update/swap 中的函数baseApi.UpdateDeviceSwap存在安全问题,使用特殊输入通过参数 Path 导致命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | 1Panel | 1.10.1-lts | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-2364 | 1.8 LOW | Musicshelf Backup androidmanifest.xml backup |
| CVE-2024-2365 | 1.6 LOW | Musicshelf SHA-1 PinningTrustManager.java weak password hash |
| CVE-2024-28757 | libexpat 安全漏洞 |
No comments yet