Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Demonstration of CVE-2014-3120 | https://github.com/jeffgeiger/es_inject | POC Details |
| 2 | POC Code to exploite CVE-2014-3120 | https://github.com/echohtp/ElasticSearch-CVE-2014-3120 | POC Details |
| 3 | None | https://github.com/xpgdgit/CVE-2014-3120 | POC Details |
| 4 | The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. Be aware this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2014/CVE-2014-3120.yaml | POC Details |
| 5 | None | https://github.com/chaitin/xray-plugins/blob/main/poc/manual/elasticsearch-cve-2014-3120.yml | POC Details |
| 6 | https://github.com/vulhub/vulhub/blob/master/elasticsearch/CVE-2014-3120/README.md | POC Details |
No public POC found.
Login to generate AI POC| CVE-2014-5105 | ol-commerce 跨站脚本漏洞 | |
| CVE-2014-5113 | Visualware MyConnection Server ‘test.php’ 跨站脚本漏洞 | |
| CVE-2014-5112 | Fonality Trixbox 安全漏洞 | |
| CVE-2014-5111 | Fonality Trixbox 目录遍历漏洞 | |
| CVE-2014-5110 | Fonality Trixbox 跨站脚本漏洞 | |
| CVE-2014-5109 | Fonality Trixbox SQL注入漏洞 | |
| CVE-2014-5108 | concrete5 跨站脚本漏洞 | |
| CVE-2014-5107 | Concrete5 跨站脚本和路径泄露漏洞 | |
| CVE-2014-5106 | Invision Power IP.Board 跨站脚本漏洞 | |
| CVE-2013-4262 | Apache Subversion 安全漏洞 | |
| CVE-2014-5104 | ol-commerce SQL注入漏洞 | |
| CVE-2014-3304 | Cisco WebEx Meetings Server 安全漏洞 | |
| CVE-2014-3303 | Cisco WebEx Meetings Server 信息泄露漏洞 | |
| CVE-2014-2975 | Silver Peak VX 跨站脚本漏洞 | |
| CVE-2014-2974 | Silver Peak VX 跨站请求伪造漏洞 | |
| CVE-2013-4840 | HP and H3C VPN Firewall Module产品安全漏洞 | |
| CVE-2013-7393 | Apache Subversion 安全漏洞 |
No comments yet