Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-7299

EPSS 0.55% · P68
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2015-7299

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via the xml parameter.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
多款K2产品SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
K2 blackpearl、smartforms和K2 for SharePoint都是美国K2公司的产品。blackpearl是一套用于构建和运行业务流程的应用程序。smartforms是一款在线业务系统推送消息产品。K2 for SharePoint是一套用于在SharePoint 2013或Office上创建表单和工作流程的应用程序。 多款K2产品的Runtime/Runtime/AjaxCall.ashx文件中存在SQL注入漏洞。远程攻击者可借助‘xml’参数利用该漏洞执行任意SQL命令。以下产品
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2015-7299

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2015-7299

登录查看更多情报信息。

Same Patch Batch · n/a · 2015-10-21 · 136 CVEs total

CVE-2015-4734Oracle Java SE和Java SE Embedded JGSS子组件
CVE-2015-4804Oracle PeopleSoft Enterprise HCM Talent Acquistion Management组件安全漏洞
CVE-2015-4803Oracle Java SE、Java SE Embedded和JRockit JAXP子组件拒绝服务漏洞
CVE-2015-4802Oracle MySQL Server Server : Partition子组件安全漏洞
CVE-2015-4801Oracle Sun Solaris Kernel Zones子组件安全漏洞
CVE-2015-4800Oracle MySQL Server Server : Optimizer子组件拒绝服务漏洞
CVE-2015-4799Oracle Fusion Middleware WebCenter Sites组件安全漏洞
CVE-2015-4798Oracle E-Business Suite Applications Technology Stack组件拒绝服务漏洞
CVE-2015-4797Oracle Supply Chain Products Suite Agile PLM组件安全漏洞
CVE-2015-4796Oracle Database Server Java VM组件安全漏洞
CVE-2015-4795Oracle Industry Applications Utilities Work and Asset Management组件安全漏洞
CVE-2015-4794Oracle Database Server Java VM组件安全漏洞
CVE-2015-4793Oracle Communications Applications Communications Convergence组件安全漏洞
CVE-2015-4792Oracle MySQL Server Server : Partition子组件拒绝服务漏洞
CVE-2015-4791Oracle MySQL Server Server : Security : Privileges子组件拒绝服务漏洞
CVE-2015-4766Oracle MySQL Server Server : Security : Firewall子组件拒绝服务漏洞
CVE-2015-4762Oracle E-Business Suite Applications DBA组件安全漏洞
CVE-2015-4913Oracle MySQL Server 远程拒绝服务漏洞
CVE-2015-4911多款Oracle产品拒绝服务漏洞
CVE-2015-4912Oracle Fusion Middleware Oracle Access Manager组件安全漏洞

Showing top 20 of 136 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2015-7299

No comments yet


Leave a comment