Progress Telerik Fiddler Everywhere 在 8.2.0 之前的版本中暴露了特权 IPC(进程间通信)功能,这使得本地低权限攻击者能够修改应用程序启动参数,并诱使用户启动该应用,从而用攻击者控制的内容替换应用程序的用户界面或设置。成功利用此漏洞可能导致 OAuth 认证令牌泄露、执行本地可访问的程序,或对应用程序生成的配置文件进行未授权的修改。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | Progress® Telerik® Fiddler® Everywhere | 1.0.0 ~ 8.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet