Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment in the HttpKernel component. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2015/CVE-2015-4050.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2015-4094 | Thycotic Password Manager Secret Server应用程序加密问题漏洞 | |
| CVE-2015-4162 | Palo Alto Networks PAN-OS XML外部实体漏洞 | |
| CVE-2015-4161 | SAP Afaria 权限许可和访问控制漏洞 | |
| CVE-2015-4160 | SAP ASE Database Platform SQL注入漏洞 | |
| CVE-2015-4159 | SAP HANA Web-based Development Workbench SQL注入漏洞 | |
| CVE-2015-4158 | SAP ABAP & Java Server 拒绝服务漏洞 | |
| CVE-2015-4157 | SAP Content Server 拒绝服务漏洞 | |
| CVE-2015-4156 | GNU Parallel 后置链接漏洞 | |
| CVE-2015-4155 | GNU Parallel 后置链接漏洞 | |
| CVE-2014-0999 | Sendio ESP 信息泄露漏洞 | |
| CVE-2015-3982 | Django cached_db后台安全漏洞 | |
| CVE-2015-2944 | Apache Sling API和Sling Servlets 跨站脚本漏洞 | |
| CVE-2015-2282 | 多款SAP产品基于栈的缓冲区溢出漏洞 | |
| CVE-2015-2278 | 多款SAP产品拒绝服务漏洞 | |
| CVE-2015-1945 | IBM InfoSphere Master Data Management Reference Data Management组件权限许可和访问控制漏洞 | |
| CVE-2015-0850 | FusionForge Git插件输入验证漏洞 | |
| CVE-2015-0759 | Cisco Headend Digital Broadband Delivery System 跨站请求伪造漏洞 | |
| CVE-2014-8391 | Sendio ESP 信息泄露漏洞 |
No comments yet