Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2004-0374

EPSS 8.31% · P92
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2004-0374

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "__SQLUSER__" string.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Interchange远程信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Interchange是一套电子商务和应用服务器系统。该系统可用于构建一个基于数据库的Web服务器以及在线应用。 Interchange不正确处理部分URI请求,远程攻击者可以利用这个漏洞获得任意变量信息,造成敏感信息泄露。 直接提交cgi-bin目录中的"__SQLUSER__"请求,可获得大量变量信息,利用这些信息,攻击者可进一步对系统进行攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2004-0374

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2004-0374

登录查看更多情报信息。

Same Patch Batch · n/a · 2004-04-06 · 11 CVEs total

CVE-2003-0648FTE多个本地缓冲区溢出漏洞
CVE-2004-0183TCPDump ISAKMP删除负载远程缓冲区溢出漏洞
CVE-2004-0184TCPDump ISAKMP标识负载远程整数溢出漏洞
CVE-2004-0366Leon J Breedt Pam-PGSQL远程SQL注入漏洞
CVE-2004-0370FreeBSD IPv6套接口选项处理本地内存泄露漏洞
CVE-2004-0371Heimdal Kerberos Cross-Realm信任假冒漏洞
CVE-2004-0376OFTPD PORT命令畸形参数远程拒绝服务攻击漏洞
CVE-2004-0377Perl win32_stat函数远程缓冲区溢出漏洞
CVE-2004-0380Microsoft Internet Explorer MT-ITS协议区域绕过漏洞
CVE-2004-0381MySQL放弃错误报告不安全临时文件建立漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2004-0374

No comments yet


Leave a comment