Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Spring by Pivotal | Spring Framework | Versions prior to 5.0.5 and 4.3.15 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Spring MVC Framework versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported are vulnerable to local file inclusion because they allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). A malicious user can send a request using a specially crafted URL that can lead a directory traversal attack. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-1271.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-1270 | Pivotal Software Spring Framework 代码注入漏洞 | |
| CVE-2018-1272 | Pivotal Spring Framework 权限许可和访问控制问题漏洞 |
No comments yet