Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-16355

EPSS 0.14% · P33
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-16355

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Phusion Passenger 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Phusion Passenger是荷兰Phusion公司的一个用于在Apache和Nginx网页服务器上部署Ruby on Rails项目的Apache模块。 Phusion Passenger 5.1.10版本中的agent/Core/SpawningKit/Spawner.h文件存在安全漏洞。攻击者可通过将REVISION文件从应用程序root文件夹符号链接到选择的文件利用该漏洞读取任意文件内容。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2017-16355

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-16355

Please Login to view more intelligence information

Same Patch Batch · n/a · 2017-12-14 · 32 CVEs total

CVE-2017-17527PasDoc 安全漏洞
CVE-2017-17672vBulletin 安全漏洞
CVE-2017-17671vBulletin for Windows 安全漏洞
CVE-2017-17684Panda Global Protection 安全漏洞
CVE-2017-17683Panda Global Protection 安全漏洞
CVE-2017-17682ImageMagick 资源管理错误漏洞
CVE-2017-17681ImageMagick 安全漏洞
CVE-2017-17680ImageMagick 安全漏洞
CVE-2017-17535Bob Hepple gjots2 安全漏洞
CVE-2017-17534Mensis 安全漏洞
CVE-2017-17533Tkabber 安全漏洞
CVE-2017-17532Kiwi 安全漏洞
CVE-2017-17531GNU GLOBAL 安全漏洞
CVE-2017-17530Geomview 注入漏洞
CVE-2017-17529AbiWord 安全漏洞
CVE-2017-17528ScummVM 安全漏洞
CVE-2016-10703ecstatic npm package 安全漏洞
CVE-2017-17526Bernard Parisse Giac 安全漏洞
CVE-2017-17525xTuple PostBooks 安全漏洞
CVE-2017-17524SWI-Prolog 安全漏洞

Showing top 20 of 32 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-16355

No comments yet


Leave a comment