Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2005-4197

EPSS 8.60% · P92
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2005-4197

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Java Applet.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Nortel SSL VPN跨站脚本/命令执行漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Nortel SSL VPN是远程访问安全解决方案,可以使用安全套接字层(SSL)做为基础安全协议。 Nortel的SSL VPN的WEB界面没有充分的验证用户输入,因此攻击者可以在某些页面的链接中隐藏命令。由于从这些页面中所调用的Java Applet是经过加密签名的,因此可能以使用浏览器用户的权限执行任意系统命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2005-4197

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-4197

Please Login to view more intelligence information

Same Patch Batch · n/a · 2005-12-13 · 23 CVEs total

CVE-2005-4200MyBB多个未明漏洞
CVE-2005-4210Opera Web 浏览器长标题元素书签拒绝服务漏洞
CVE-2005-4209Alt-N MDaemon/WorldClient邮件标题跨站脚本攻击漏洞
CVE-2005-4208Flatnuke Index.PHP 目录遍历漏洞
CVE-2005-4207BTGrup Admin WebController SQL 注入漏洞
CVE-2005-4206Blackboard Academic Suite Frameset.JSP 跨域框架集导入漏洞
CVE-2005-4205LocazoList Classifieds SearchDB.ASP 输入验证漏洞
CVE-2005-4204LogiSphere 跨站脚本攻击漏洞
CVE-2005-4203LogiSphere 拒绝服务攻击漏洞
CVE-2005-4202LogiSphere 多个目录遍历漏洞
CVE-2005-4201My Album Online未指定目录遍历漏洞
CVE-2005-3352Apache 'mod_imap' Referer 跨站脚本漏洞
CVE-2005-4199MyBB 多个SQL 注入漏洞
CVE-2005-4198Netref Index.PHP SQL 注入漏洞
CVE-2005-4196Scout Portal 工具集多个输入验证漏洞
CVE-2005-4195Scout Portal 工具集 'ParentId' 参数 SQL 注入漏洞
CVE-2005-4194Sights'n Sound MediaServerListing.exe缓冲区溢出漏洞
CVE-2005-4193UseBB PHP_SELF 跨站脚本漏洞
CVE-2005-4192Horde Nag远程HTML注入漏洞
CVE-2005-4191Horde Nag远程HTML注入漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2005-4197

No comments yet


Leave a comment