SolarWinds serv-u是美国SolarWinds公司的一款文件传输服务器。 SolarWinds Serv-U 15.5.4 HF1版本及之前版本存在授权问题漏洞,该漏洞源于不安全的直接对象引用(IDOR),可能导致远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SolarWinds | Serv-U | 15.5.4 HF1 and below |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SolarWinds | Serv-U | 15.5.4 HF1 and below | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28315 | 6.2 MEDIUM | SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability |
| CVE-2026-28307 | 4.7 MEDIUM | SolarWinds Serv-U Privilege Escalation Vulnerability |
| CVE-2026-28317 | 4.7 MEDIUM | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-28309 | 4.7 MEDIUM | SolarWinds Serv-U Broken Access Control Vulnerability |
| CVE-2026-28310 | 4.7 MEDIUM | SolarWinds Serv-U Privilege Escalation Vulnerability |
| CVE-2026-28321 | 4.7 MEDIUM | SolarWinds Serv-U Broken Access Control Vulnerability |
| CVE-2026-28313 | 4.7 MEDIUM | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-28316 | 4.7 MEDIUM | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-28306 | 4.7 MEDIUM | SolarWinds Serv-U Privilege Escalation Vulnerability |
| CVE-2026-28304 | 4.7 MEDIUM | SolarWinds Serv-U Remote Code Execution Vulnerability |
| CVE-2026-28302 | 4.7 MEDIUM | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-28305 | 4.7 MEDIUM | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-28314 | 4.7 MEDIUM | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
| CVE-2026-28312 | 4.7 MEDIUM | SolarWinds Serv-U Privilege Escalation Vulnerability |
No comments yet