Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-0886

EPSS 4.25% · P89
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-0886

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware before 1.4.0.49.2 allow remote attackers to (1) hijack the intranet connectivity of arbitrary users for requests that perform a login via goform/login, or hijack the authentication of administrators for requests that (2) enable external logins via an mso_remote_enable action to goform/RemoteRange or (3) change DNS settings via a manual_dns_enable action to goform/Basic.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Smc_Networks SMC SMCD3G-CCR web界面多个跨站请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
带有1.4.0.49.2之前版本固件的SMC SMCD3G-CCR(又名Comcast Business Gateway)的web界面中存在多个跨站请求伪造漏洞。远程攻击者可以(1)借助goform/login劫持任意用户执行登录的内网连接,(2)借助对goform/RemoteRange的mso_remote_enable操作劫持管理员启用外部登陆的认证,(3)或借助对goform/Basic的manual_dns_enable操作改变DNS设置。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-0886

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-0886

登录查看更多情报信息。

Same Patch Batch · n/a · 2011-02-08 · 21 CVEs total

CVE-2011-0915IBM Lotus Domino nrouter.exe栈缓冲区溢出漏洞
CVE-2011-0910Vanilla Forums cookie实现任意用户账户访问漏洞
CVE-2011-0909Vanilla Forums跨站脚本攻击漏洞
CVE-2011-0908Vanilla Forums开放重定向漏洞
CVE-2011-0526Vanilla Forums index.php跨站脚本攻击漏洞
CVE-2011-0920IBM Lotus Domino远程控制台认证绕过和任意代码执行漏洞
CVE-2011-0919IBM Lotus Domino POP3和IMAP服务多个栈缓冲区溢出漏洞
CVE-2011-0918IBM Lotus Domino Nrouter服务栈缓冲区溢出漏洞
CVE-2011-0917IBM Lotus Domino nLDAP.exe缓冲区溢出漏洞
CVE-2011-0916IBM Lotus Domino SMTP服务栈缓冲区溢出漏洞
CVE-2010-4728Zikula rand和srand PHP函数加密问题漏洞
CVE-2011-0914IBM Lotus Domino服务器DIIOP实现ndiiop.exe整数符号错误漏洞
CVE-2011-0913IBM Lotus Domino服务器DIIOP实现ndiiop.exe栈缓冲区溢出漏洞
CVE-2011-0912IBM Lotus Notes参数注入漏洞
CVE-2011-0911Zikula Users模块跨站脚本攻击漏洞
CVE-2011-0887Smc_Networks SMC SMCD3G-CCR web管理门户会话劫持漏洞
CVE-2011-0885Smc_Networks SMC SMCD3G-CCR Comcast Business Gateway配置信任管理漏洞
CVE-2011-0538Wireshark '.pcap'文件内存破坏漏洞
CVE-2011-0535Zikula Users模块跨站请求伪造漏洞
CVE-2010-4729Zikula跨站请求伪造漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2011-0886

No comments yet


Leave a comment