Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-1000139

EPSS 0.21% · P43
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-1000139

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Catalyst Mahara 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Catalyst Mahara是新西兰Catalyst IT公司的一套社交网络系统。该系统包含博客、履历表生成器、文件管理器等。 Catalyst Mahara中存在安全漏洞,该漏洞源于程序并没有对curl重定向的全部进程针对黑白名单进行检测。攻击者可利用该漏洞实施服务器端请求伪造攻击。以下版本受到影响:Mahara 1.8.7之前的1.8版本,1.9.5之前的1.9版本,1.10.3之前的1.10版本,15.04.0之前的15.04版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2017-1000139

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-1000139

登录查看更多情报信息。

Same Patch Batch · n/a · 2017-11-03 · 32 CVEs total

CVE-2017-1000148Catalyst Mahara 安全漏洞
CVE-2017-16516Ruby yajl-ruby gem 安全漏洞
CVE-2017-16237TG Vir.IT eXplorer Anti-Virus 安全漏洞
CVE-2017-16513Ipswitch WS_FTP Professional 缓冲区错误漏洞
CVE-2017-16523MitraStar GPT-2541GNAC (HGU)和DSL-100HN-T1 安全漏洞
CVE-2017-16522MitraStar GPT-2541GNAC (HGU)和DSL-100HN-T1 安全漏洞
CVE-2017-1000171Catalyst Mahara Mobile 安全漏洞
CVE-2017-1000157Catalyst Mahara 安全漏洞
CVE-2017-1000156Catalyst Mahara 安全漏洞
CVE-2017-1000155Catalyst Mahara 安全漏洞
CVE-2017-1000154Catalyst Mahara 安全漏洞
CVE-2017-1000153Catalyst Mahara 安全漏洞
CVE-2017-1000152Catalyst Mahara 安全漏洞
CVE-2017-1000151Catalyst Mahara 安全漏洞
CVE-2017-1000150Catalyst Mahara 安全漏洞
CVE-2017-1000149Catalyst Mahara 跨站脚本漏洞
CVE-2017-1000131Catalyst Mahara 安全漏洞
CVE-2017-1000147Catalyst Mahara 安全漏洞
CVE-2017-1000146Catalyst Mahara 跨站脚本漏洞
CVE-2017-1000145Catalyst Mahara 安全漏洞

Showing top 20 of 32 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-1000139

No comments yet


Leave a comment