Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an admin logs into My Cloud, a server-side session is created that is bound to the user's IP address. After the session is created, it is possible to call authenticated CGI modules by sending the cookie username=admin in the HTTP request. The invoked CGI will check if a valid session is present and bound to the user's IP address.) It was found that it is possible for an unauthenticated attacker to create a valid session without a login. The network_mgr.cgi CGI module contains a command called \"cgi_get_ipv6\" that starts an admin session -- tied to the IP address of the user making the request -- if the additional parameter \"flag\" with the value \"1\" is provided. Subsequent invocation of commands that would normally require admin privileges now succeed if an attacker sets the username=admin cookie. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-17153.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-17178 | Neato Botvac Connected 安全漏洞 | |
| CVE-2018-17111 | Coinlancer 安全漏洞 | |
| CVE-2018-17071 | Lucky9io 安全漏洞 | |
| CVE-2018-16820 | Monstra CMS 路径遍历漏洞 | |
| CVE-2018-16819 | Monstra CMS 安全漏洞 | |
| CVE-2018-16794 | Microsoft Active Directory Federation Services 安全漏洞 | |
| CVE-2018-16515 | Matrix Synapse 安全漏洞 | |
| CVE-2018-16225 | Askey QBee MultiSensor Camera 授权问题漏洞 | |
| CVE-2018-15546 | Accusoft PrizmDoc 跨站脚本漏洞 | |
| CVE-2018-13982 | New Digital Group Smarty 路径遍历漏洞 | |
| CVE-2018-16671 | CIRCONTROL CirCarLife 信息泄露漏洞 | |
| CVE-2018-16670 | CIRCONTROL CirCarLife 安全漏洞 | |
| CVE-2018-16669 | CirCarLife和PowerStudio CIRCONTROL Open Charge Point Protocol 安全漏洞 | |
| CVE-2018-16668 | CIRCONTROL CirCarLife | |
| CVE-2017-6913 | Open-Xchange webmail 跨站脚本漏洞 | |
| CVE-2018-1000802 | Python 命令注入漏洞 | |
| CVE-2018-17177 | Neato Robotics Botvac Connected和Neato Robotics Botvac 85 加密问题漏洞 | |
| CVE-2018-17176 | Neato Botvac Connected 授权问题漏洞 | |
| CVE-2018-11300 | Android Qualcomm WLAN Host 安全漏洞 | |
| CVE-2018-11286 | Android Video 安全漏洞 |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet