尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an admin logs into My Cloud, a server-side session is created that is bound to the user's IP address. After the session is created, it is possible to call authenticated CGI modules by sending the cookie username=admin in the HTTP request. The invoked CGI will check if a valid session is present and bound to the user's IP address.) It was found that it is possible for an unauthenticated attacker to create a valid session without a login. The network_mgr.cgi CGI module contains a command called \"cgi_get_ipv6\" that starts an admin session -- tied to the IP address of the user making the request -- if the additional parameter \"flag\" with the value \"1\" is provided. Subsequent invocation of commands that would normally require admin privileges now succeed if an attacker sets the username=admin cookie. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-17153.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2018-17178 | Neato Botvac Connected 安全漏洞 | |
| CVE-2018-17111 | Coinlancer 安全漏洞 | |
| CVE-2018-17071 | Lucky9io 安全漏洞 | |
| CVE-2018-16820 | Monstra CMS 路径遍历漏洞 | |
| CVE-2018-16819 | Monstra CMS 安全漏洞 | |
| CVE-2018-16794 | Microsoft Active Directory Federation Services 安全漏洞 | |
| CVE-2018-16515 | Matrix Synapse 安全漏洞 | |
| CVE-2018-16225 | Askey QBee MultiSensor Camera 授权问题漏洞 | |
| CVE-2018-15546 | Accusoft PrizmDoc 跨站脚本漏洞 | |
| CVE-2018-13982 | New Digital Group Smarty 路径遍历漏洞 | |
| CVE-2018-16671 | CIRCONTROL CirCarLife 信息泄露漏洞 | |
| CVE-2018-16670 | CIRCONTROL CirCarLife 安全漏洞 | |
| CVE-2018-16669 | CirCarLife和PowerStudio CIRCONTROL Open Charge Point Protocol 安全漏洞 | |
| CVE-2018-16668 | CIRCONTROL CirCarLife | |
| CVE-2017-6913 | Open-Xchange webmail 跨站脚本漏洞 | |
| CVE-2018-1000802 | Python 命令注入漏洞 | |
| CVE-2018-17177 | Neato Robotics Botvac Connected和Neato Robotics Botvac 85 加密问题漏洞 | |
| CVE-2018-17176 | Neato Botvac Connected 授权问题漏洞 | |
| CVE-2018-11300 | Android Qualcomm WLAN Host 安全漏洞 | |
| CVE-2018-11286 | Android Video 安全漏洞 |
显示前 20 条,共 31 条。 查看全部 → →
暂无评论