Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | mongo-express | All versions prior to version 0.54.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/masahiro331/CVE-2019-10758 | POC Details |
| 2 | CVE-2019-10758 | https://github.com/lp008/CVE-2019-10758 | POC Details |
| 3 | mongo-express before 0.54.0 is vulnerable to remote code execution via endpoints that uses the `toBSON` method and misuse the `vm` dependency to perform `exec` commands in a non-safe environment. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-10758.yaml | POC Details |
| 4 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/mongo-express%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2019-10758.md | POC Details |
| 5 | Mongo Express CVE-2019-10758 Code Execution | https://github.com/chaitin/xray-plugins/blob/main/poc/manual/mongo-express-cve-2019-10758.yml | POC Details |
| 6 | https://github.com/vulhub/vulhub/blob/master/mongo-express/CVE-2019-10758/README.md | POC Details |
No public POC found.
Login to generate AI POC| CVE-2019-18249 | Reliable Controls MACH-ProWebSys和Reliable Controls MACH-ProWebCom 跨站脚本漏洞 | |
| CVE-2019-19949 | ImageMagick Studio ImageMagick 缓冲区错误漏洞 | |
| CVE-2019-19952 | ImageMagick Studio ImageMagick 资源管理错误漏洞 | |
| CVE-2019-19953 | GraphicsMagick 缓冲区错误漏洞 | |
| CVE-2019-19951 | GraphicsMagick 缓冲区错误漏洞 | |
| CVE-2019-19950 | GraphicsMagick 资源管理错误漏洞 | |
| CVE-2019-19948 | ImageMagick Studio ImageMagick 缓冲区错误漏洞 | |
| CVE-2017-16778 | Fermax Outdoor Panel DTMF tone receiver 访问控制错误漏洞 | |
| CVE-2019-19954 | Signal Desktop 代码问题漏洞 | |
| CVE-2019-19960 | wolfSSL 安全漏洞 | |
| CVE-2019-19956 | libxml2 安全漏洞 | |
| CVE-2019-19923 | SQLite 代码问题漏洞 | |
| CVE-2019-19924 | SQLite 安全漏洞 | |
| CVE-2019-19925 | SQLite 代码问题漏洞 | |
| CVE-2019-19957 | libIEC61850 缓冲区错误漏洞 | |
| CVE-2019-19958 | libIEC61850 资源管理错误漏洞 | |
| CVE-2019-19963 | wolfSSL 安全漏洞 | |
| CVE-2019-19962 | wolfSSL 加密问题漏洞 |
No comments yet