Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | PHPMyAdmin v4.8.0 and v.4.8.1 LFI exploit | https://github.com/0x00-0x00/CVE-2018-12613 | POC Details |
| 2 | Modified standalone exploit ported for Python 3 | https://github.com/ivanitlearning/CVE-2018-12613 | POC Details |
| 3 | 这篇文章将分享一个phpMyAdmin 4.8.1版本的文件包含漏洞,从配置到原理,再到漏洞复现进行讲解,更重要的是让大家了解这些真实漏洞背后的知识。基础性文章,希望对您有所帮助! | https://github.com/eastmountyxz/CVE-2018-12613-phpMyAdmin | POC Details |
| 4 | PhpMyAdmin before version 4.8.2 is susceptible to local file inclusion that allows an attacker to include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication). | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-12613.yaml | POC Details |
| 5 | None | https://github.com/chaitin/xray-plugins/blob/main/poc/manual/phpmyadmin-cve-2018-12613-file-inclusion.yml | POC Details |
| 6 | https://github.com/vulhub/vulhub/blob/master/phpmyadmin/CVE-2018-12613/README.md | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-0306 | 多款Cisco产品NX-OS Software CLI解析器输入验证错误漏洞 | |
| CVE-2018-0373 | Cisco AnyConnect Secure Mobility Client for Windows Desktop 输入验证漏洞 | |
| CVE-2018-0371 | Cisco Acano X-Series、Meeting Server 1000和Meeting Server 2000 Web Admin Interface 输入验证漏洞 | |
| CVE-2018-0365 | Cisco Firepower Management Center 跨站请求伪造漏洞 | |
| CVE-2018-0364 | Cisco Unified Communications Domain Manager 跨站请求伪造漏洞 | |
| CVE-2018-0363 | Cisco Unified Communications Manager IM & Presence Service 跨站请求伪造漏洞 | |
| CVE-2018-0362 | Cisco 5000 Series Enterprise Network Compute System和UCS E-Series Servers 授权问题漏洞 | |
| CVE-2018-0359 | Cisco Meeting Server 安全漏洞 | |
| CVE-2018-0358 | Cisco TelePresence Video Communication Server Expressway 安全漏洞 | |
| CVE-2018-0337 | Cisco NX-OS Software 输入验证错误漏洞 | |
| CVE-2018-0331 | 多款Cisco产品NX-OS Software Discovery Protocol子系统资源管理错误漏洞 | |
| CVE-2018-0313 | 多款Cisco产品NX-OS Software 输入验证漏洞 | |
| CVE-2018-0311 | 多款Cisco产品FXOS Software和NX-OS Software Fabric Services组件资源管理错误漏洞 | |
| CVE-2018-0310 | 多款Cisco产品FXOS Software和NX-OS Software Fabric Services组件资源管理错误漏洞 | |
| CVE-2018-0309 | Cisco Nexus 3000和9000 Series Switches NX-OS 安全漏洞 | |
| CVE-2018-12630 | NEWMARK NMCMS SQL注入漏洞 | |
| CVE-2018-0305 | 多款Cisco产品FXOS Software和NX-OS Software Fabric Services组件安全漏洞 | |
| CVE-2018-0303 | 多款Cisco产品FXOS Software和NX-OS Software Discovery Protocol组件输入验证漏洞 | |
| CVE-2018-0302 | 多款Cisco产品FXOS Software和UCS Fabric Interconnect Software CLI解析器输入验证错误漏洞 | |
| CVE-2018-0300 | Cisco Firepower 4100 Series Next-Generation Firewall和Firepower 9300 Security Appliance 路径遍 |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet