在适用于 Windows 的 In Progress® Telerik® Fiddler® Classic 中,v6.0.20262.10021 之前的版本存在一个完整性检查不充分的问题。当应用程序启动外部辅助工具时,其完整性验证机制仅检查该文件是否具备有效的 Authenticode 签名,且该签名的证书主题名称是否匹配一个宽泛的允许发布商名称片段列表,而未进一步验证该文件是否为该产品特定版本所附带的特定可执行文件。 本地低权限攻击者若将其中一个辅助可执行文件替换为来自已允许发布商的其他有效签名的二进制文件,即可
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | Progress® Telerik® Fiddler® Classic | 1.0.0 ~ 6.0.20262.10021 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92931 | 8.8 HIGH | CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Renderer SDK |
| CVE-2026-77804 | 6.6 MEDIUM | Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Installation in Prog |
| CVE-2026-77802 | 6.3 MEDIUM | HTTP Request Smuggling Vulnerability in Progress® Telerik® Fiddler® Classic |
| CVE-2026-77803 | 3.6 LOW | Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic |
No comments yet