Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-16244

EPSS 0.40% · P61
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-16244

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack bypasses a protection mechanism involving X-CSRF headers and CSRF tokens via a certain _handler postback variable.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
OctoberCMS 跨站请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OctoberCMS是加拿大软件开发者Alexey Bobkov和澳大利亚软件开发者Samuel Georges共同研发的一套开源的、自托管的建立在Laravel PHP框架基础上的内容管理系统(CMS)。 OctoberCMS 1.0.426(又名Build 426)版本中存在跨站请求伪造漏洞,该漏洞源于程序在处理postback时没有正确的验证跨站请求伪造令牌。远程攻击者可借助certain _handler postback变量利用该漏洞绕过保护机制,控制用户账户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2017-16244

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-16244

登录查看更多情报信息。

Same Patch Batch · n/a · 2017-11-01 · 21 CVEs total

CVE-2017-1000242CloudBees Jenkins Git Client插件安全漏洞
CVE-2017-16248Perl Catalyst-Plugin-Static-Simple模块安全漏洞
CVE-2017-15535MongoDB 安全漏洞
CVE-2017-14376EMC AppSync Server 安全漏洞
CVE-2017-14375多款EMC产品安全漏洞
CVE-2017-14027多款Korenix产品安全漏洞
CVE-2017-14021多款Korenix产品安全漏洞
CVE-2017-1000245CloudBees Jenkins SSH插件安全漏洞
CVE-2017-1000244CloudBees Jenkins Favorite插件跨站请求伪造漏洞
CVE-2017-1000243CloudBees Jenkins Favorite插件安全漏洞
CVE-2017-1000121WebKit和WebKitGTK+ 安全漏洞
CVE-2017-16353GraphicsMagick 信息泄露漏洞
CVE-2017-16352GraphicsMagick 缓冲区错误漏洞
CVE-2017-16359radare 安全漏洞
CVE-2017-16358radare 缓冲区错误漏洞
CVE-2017-16357radare 缓冲区错误漏洞
CVE-2017-15918Sera 安全漏洞
CVE-2017-15566SchedMD Slurm 安全漏洞
CVE-2017-14992Docker-CE 安全漏洞
CVE-2017-1000122WebKit和WebKitGTK+ 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2017-16244

No comments yet


Leave a comment