Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2013-3520

EPSS 81.91% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2013-3520

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
VMware vCenter Chargeback Manager 代码注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
VMware vCenter Chargeback Manager是美国威睿(VMware)公司的一款可实现准确的虚拟机成本测算、分析和报告的产品。该产品提供创建满足组织需求的自定义成本模型和衡量指标、准确地了解虚拟化成本和实现“IT即服务”交付功能。 VMware vCenter Chargeback Manager (又名CBM) 2.5.0及之前的版本中存在漏洞,该漏洞源于程序没有正确处理上传。远程攻击者可利用该漏洞执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2013-3520

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-3520

登录查看更多情报信息。

Same Patch Batch · n/a · 2013-06-17 · 21 CVEs total

CVE-2013-4608REDCap 跨站脚本漏洞
CVE-2013-3643Android平台的Galapagos Browser应用程序信息泄露漏洞
CVE-2013-3642Android平台的Angel Browser应用程序信息泄露漏洞
CVE-2013-3026IBM Lotus Quickr for Domino ActiveX Control 缓冲区溢出漏洞
CVE-2013-2310SoftBank Wi-Fi Spot Configuration Software 信息泄露漏洞
CVE-2013-2309OpenPNE 跨站脚本漏洞
CVE-2013-4612REDCap 多个跨站脚本漏洞
CVE-2013-4611REDCap 多个安全漏洞
CVE-2013-4610REDCap 数据输入表单Data Search工具安全漏洞
CVE-2013-4609REDCap 权限许可和访问控制问题漏洞
CVE-2012-6564REDCap 跨站脚本漏洞
CVE-2013-2981IBM Data Studio 目录遍历漏洞
CVE-2013-2980IBM Data Studio Web Console 跨站请求伪造漏洞
CVE-2013-1097Novell ZENworks Configuration Management 跨站脚本漏洞
CVE-2013-1095Novell ZENworks Configuration Management 反射XSS跨站脚本漏洞
CVE-2013-1094Novell ZENworks Configuration Management 跨站脚本漏洞
CVE-2013-1093Novell ZENworks Configuration Management 开放重定向漏洞
CVE-2012-6567REDCap 输入验证漏洞
CVE-2012-6566REDCap 跨站脚本漏洞
CVE-2012-6565REDCap 跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2013-3520

No comments yet


Leave a comment