眈眈探求 | 详情
-
- 9eec9b49bcdcc9ac24a0a8c9a5d5f95b |
- CVE-2024-28145 |
- 2024-12-12 14:15:22 |
- An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword. |
- 详情 |
-
-
-
- 4fdbf33748ea75d38f8ac045aa306ab1 |
- CVE-2024-28144 |
- 2024-12-12 14:15:22 |
- An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user. |
- 详情 |
-
-
-
- 86635ea38a607f675e45bb2bf0366706 |
- CVE-2024-28143 |
- 2024-12-12 14:15:22 |
- The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter for a user without knowing the old password, e.g. by exploiting a CSRF issue. |
- 详情 |
-
-
-
- 4e9561c1fb555057a93fac88536ab6e5 |
- CVE-2024-54122 |
- 2024-12-12 13:15:11 |
- Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may affect availability. |
- 详情 |
-
-
-
- 9dbaef59d3a24333acacb4140a88c412 |
- CVE-2024-54119 |
- 2024-12-12 13:15:11 |
- Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. |
- 详情 |
-
-
-
- 244f204acbee1ff428f99af6afe94fe3 |
- CVE-2024-54118 |
- 2024-12-12 13:15:11 |
- Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. |
- 详情 |
-
-
-
- 57dcc095861454525aa6f1b55d69d1e3 |
- CVE-2024-47947 |
- 2024-12-12 13:15:10 |
- Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "Edit Disclaimer Text" function of the configuration menu is vulnerable to stored XSS. Only the users Poweruser and Admin can use this function which is available at the URL https://$SCANNER/cgi/admin.cgi?-rdisclaimer+-apre The stored Javascript payload will be executed every time the ScanWizard is loaded, even in the Kiosk-mode browser. |
- 详情 |
-
-
-
- 5ffff2d21aa74e70384e62daeca48dd1 |
- CVE-2024-36498 |
- 2024-12-12 13:15:10 |
- Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "Edit Disclaimer Text" function of the configuration menu is vulnerable to stored XSS. Only the users Poweruser and Admin can use this function which is available at the URL https://$SCANNER/cgi/admin.cgi?-rdisclaimer+-apre The stored Javascript payload will be executed every time the ScanWizard is loaded, even in the Kiosk-mode browser. Version 7.40 implemented a fix, but it could be bypassed via URL-encoding the Javascript payload again. |
- 详情 |
-
-
@@ -1990,7 +1990,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
Online Marriage Registration System跨站脚本漏洞 |
详情 |
@@ -1998,7 +1998,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
WordPress plugin Elementor信息泄露漏洞 |
详情 |
@@ -2006,7 +2006,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
WordPress plugin Slimstat Analytics跨站脚本漏洞 |
详情 |
@@ -2014,7 +2014,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
WordPress plugin WPIDE信息泄露漏洞 |
详情 |
@@ -2022,7 +2022,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
HCL BigFix Platform命令执行漏洞 |
详情 |
@@ -2030,7 +2030,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
Automatic Systems SlimLane权限提升漏洞 |
详情 |
@@ -2038,7 +2038,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
Automatic Systems SlimLane跨站脚本漏洞 |
详情 |
@@ -2046,7 +2046,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
Astro跨站脚本漏洞 |
详情 |
@@ -2054,7 +2054,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
Hideez com.hideez信息泄露漏洞 |
详情 |
@@ -2062,7 +2062,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
DS Browsers allvideo.downloader.browser代码注入漏洞 |
详情 |
@@ -2070,7 +2070,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
D-Link DIR-820L远程代码执行漏洞 |
详情 |
@@ -2078,7 +2078,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
INATRONIC com.inatronic.drivedeck.home信息泄露漏洞 |
详情 |
@@ -2086,7 +2086,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
SAP NetWeaver AS Java身份认证次数限制错误漏洞 |
详情 |
@@ -2094,7 +2094,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
CERT Coordination Center VINCE拒绝服务漏洞 |
详情 |
@@ -2102,7 +2102,7 @@ 眈眈探求 |
+ 2024-12-13 09:24:42 |
Automatic Systems SlimLane信息泄露漏洞 |
详情 |