Netentsec NS-ASG Application Security Gateway是中国网康(Netentsec)公司的一款应用安全网关。 Netentsec NS-ASG Application Security Gateway 6.3版本存在安全漏洞,该漏洞源于文件/vpnweb/resetpwd/resetpwd.php的参数UserId会导致xpath表达式中数据的不正确中和。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Netentsec | NS-ASG Application Security Gateway | 6.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-2647 | 7.3 HIGH | Netentsec NS-ASG Application Security Gateway singlelogin.php sql injection |
| CVE-2024-2644 | 6.3 MEDIUM | Netentsec NS-ASG Application Security Gateway addfirewall.php sql injection |
| CVE-2024-2646 | 6.3 MEDIUM | Netentsec NS-ASG Application Security Gateway sql injection |
| CVE-2024-2649 | 6.3 MEDIUM | Netentsec NS-ASG Application Security Gateway deleteonlineuser.php sql injection |
| CVE-2024-2648 | 4.3 MEDIUM | Netentsec NS-ASG Application Security Gateway naccheck.php xpath injection |
No comments yet