Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2005-1201

EPSS 12.78% · P94

Public Exploits 1

Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2005-1201

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. (dot dot) in the URL to admin_avatar.php or admin_attachment.php or (2) remote attackers to enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays a different message when a file exists or does not exist.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
MAZ Bulletin board (AZbb) 1.0.08目录遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
MAZ Bulletin board (AZbb) 1.0.08版本中的多个目录遍历漏洞,允许(1)具有管理员权限的远程验证用户通过admin_avatar.php或admin_attachment.php的URL中的..(参数中包含'..')来删除任意文件,或允许(2)远程攻击者通过attachment.php的attachment参数中的..(参数中包含'..')来枚举文件,从而在文件存在或不存在的情况下显示相反的消息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2005-1201

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-1201

登录查看更多情报信息。

Vendor Advisories for CVE-2005-1201 (3)

Mailing List Discussions for CVE-2005-1201 (1)

Other References for CVE-2005-1201 (2)

Same Patch Batch · n/a · 2005-04-21 · 83 CVEs total

CVE-2001-1466VanDyke SecureCRT缓冲区溢出漏洞
CVE-2001-1476SSH用户密码猜测漏洞
CVE-2001-1463SolarWinds Serv-U File Server 加密问题漏洞
CVE-2001-1464Crystal Reports密码获得漏洞
CVE-2001-1462RSA SecurID WebID调试方式信息泄露漏洞
CVE-2001-1459OpenSSH PAM会话逃避漏洞
CVE-2001-1458Novell Groupwise任意文件取回漏洞
CVE-2001-1457CrazyWWWBoard缓冲区溢出漏洞
CVE-2001-1456基于Unix的Gauntlet Firewall和WebShield CSMAP以及smap/smapd缓冲区溢出漏洞
CVE-2001-1460PostNuke未认证的用户登录漏洞
CVE-2001-1465SurfControl SuperScout绕过过滤漏洞
CVE-2001-1467expect漏洞
CVE-2001-1468phpSecurePages包括文件任意命令执行漏洞
CVE-2001-1469SSH1 RC4消息修改漏洞
CVE-2001-1470SSH1 IDEA密码无侦查块修改漏洞
CVE-2001-1471phpBB Page Header远程任意命令执行漏洞
CVE-2001-1472PHPBB远程SQL注入操作漏洞
CVE-2001-1473SSH-1协议私钥计算漏洞
CVE-2001-1474SSH连接重定向漏洞
CVE-2001-1475SSH消息重放漏洞

Showing top 20 of 83 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2005-1201

No comments yet


Leave a comment