Progress Software MOVEit等都是美国Progress Software公司的产品。Progress Software MOVEit是一个安全托管文件传输软件。Progress Software LoadMaster是一系列应用交付控制器和负载均衡产品。Progress Software ECS Connections Manager是一个对象存储流量管理平台。 Progress Software多款产品存在命令注入漏洞,该漏洞源于多个命令端点未清理输入,可能导致未经身份验证的攻击者在
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress Software | ECS Connections Manager | V7.2.60.0< V7.2.63.2 |
affected |
| Progress Software | LoadMaster | V7.2.60.0< V7.2.63.2 |
affected |
V7.2.45.12< V7.2.54.18 |
affected | ||
| Progress Software | MOVEit WAF | V7.2.60.0< V7.2.63.2 |
affected |
| Progress Software | Object Scale Connection Manager | V7.2.60.0< V7.2.63.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | LoadMaster | V7.2.60.0 ~ V7.2.63.2 | - |
|
| Progress Software | ECS Connections Manager | V7.2.60.0 ~ V7.2.63.2 | - |
|
| Progress Software | Object Scale Connection Manager | V7.2.60.0 ~ V7.2.63.2 | - |
|
| Progress Software | MOVEit WAF | V7.2.60.0 ~ V7.2.63.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-8037.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet