Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-0910

EPSS 0.24% · P47
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-0910

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain access to arbitrary user accounts, via HMAC timing attacks.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Vanilla Forums cookie实现任意用户账户访问漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Vanilla Forums 是一个开源,符合标准的,多语言,支持主题和插件拓展的网络论坛。 Vanilla Forums 2.0.17.6之前版本中的cookie实现中存在漏洞。远程攻击者更容易借助HMAC定时攻击欺骗已签名请求,并进而获得对任意用户账户的访问。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-0910

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-0910

登录查看更多情报信息。

Same Patch Batch · n/a · 2011-02-08 · 21 CVEs total

CVE-2011-0914IBM Lotus Domino服务器DIIOP实现ndiiop.exe整数符号错误漏洞
CVE-2011-0909Vanilla Forums跨站脚本攻击漏洞
CVE-2011-0908Vanilla Forums开放重定向漏洞
CVE-2011-0526Vanilla Forums index.php跨站脚本攻击漏洞
CVE-2011-0920IBM Lotus Domino远程控制台认证绕过和任意代码执行漏洞
CVE-2011-0919IBM Lotus Domino POP3和IMAP服务多个栈缓冲区溢出漏洞
CVE-2011-0918IBM Lotus Domino Nrouter服务栈缓冲区溢出漏洞
CVE-2011-0917IBM Lotus Domino nLDAP.exe缓冲区溢出漏洞
CVE-2011-0916IBM Lotus Domino SMTP服务栈缓冲区溢出漏洞
CVE-2011-0915IBM Lotus Domino nrouter.exe栈缓冲区溢出漏洞
CVE-2010-4728Zikula rand和srand PHP函数加密问题漏洞
CVE-2011-0913IBM Lotus Domino服务器DIIOP实现ndiiop.exe栈缓冲区溢出漏洞
CVE-2011-0912IBM Lotus Notes参数注入漏洞
CVE-2011-0911Zikula Users模块跨站脚本攻击漏洞
CVE-2011-0887Smc_Networks SMC SMCD3G-CCR web管理门户会话劫持漏洞
CVE-2011-0886Smc_Networks SMC SMCD3G-CCR web界面多个跨站请求伪造漏洞
CVE-2011-0885Smc_Networks SMC SMCD3G-CCR Comcast Business Gateway配置信任管理漏洞
CVE-2011-0538Wireshark '.pcap'文件内存破坏漏洞
CVE-2011-0535Zikula Users模块跨站请求伪造漏洞
CVE-2010-4729Zikula跨站请求伪造漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2011-0910

No comments yet


Leave a comment