Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Citrix SD-WAN Center is susceptible to local file inclusion via the applianceSettingsFileTransfer function in ApplianceSettingsController. The function does not sufficiently validate or sanitize HTTP request parameter values used to construct a file system path. An attacker can trigger this vulnerability by routing traffic through the Collector controller and supplying a crafted value for filename, filedata, and workspace_id, therefore being able to write files to locations writable by the www-data user and/or to write a crafted PHP file to /home/talariuser/www/app/webroot/files/ to execute arbitrary PHP code. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-12990.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2019-13360 | CentOS Web Panel 授权问题漏洞 | |
| CVE-2018-13442 | SolarWinds Network Performance Monitor SQL注入漏洞 | |
| CVE-2019-12834 | HT2 Labs Learning Locker 跨站脚本漏洞 | |
| CVE-2019-12985 | Citrix Systems SD-WAN Center和NetScaler SD-WAN Center 命令操作系统命令注入漏洞 | |
| CVE-2019-12986 | Citrix Systems SD-WAN Center和NetScaler SD-WAN Center 命令操作系统命令注入漏洞 | |
| CVE-2019-12987 | Citrix Systems SD-WAN和NetScaler SD-WAN 命令操作系统命令注入漏洞 | |
| CVE-2019-12988 | Citrix Systems SD-WAN Center和NetScaler SD-WAN Center 命令操作系统命令注入漏洞 | |
| CVE-2019-12989 | Citrix Systems SD-WAN Appliance和NetScaler SD-WAN Appliance SQL注入漏洞 | |
| CVE-2019-12991 | Citrix Systems SD-WAN Appliance和NetScaler SD-WAN Appliance 命令操作系统命令注入漏洞 | |
| CVE-2019-12992 | Citrix Systems SD-WAN Center和NetScaler SD-WAN Center 命令操作系统命令注入漏洞 | |
| CVE-2019-13359 | CentOS Web Panel 代码问题漏洞 | |
| CVE-2019-13115 | libssh2 输入验证错误漏洞 | |
| CVE-2019-13383 | CentOS Web Panel 信息泄露漏洞 | |
| CVE-2019-13603 | HID Global DigitalPersona U.are.U 4500 Fingerprint Reader Windows Biometric Framework driv | |
| CVE-2019-13605 | CentOS Web Panel 授权问题漏洞 | |
| CVE-2019-13618 | GPAC 缓冲区错误漏洞 | |
| CVE-2019-13617 | NGINX njs 缓冲区错误漏洞 | |
| CVE-2019-13615 | VideoLAN VLC media player MKV模块libebml 缓冲区错误漏洞 | |
| CVE-2018-19629 | Hyland Software Perceptive Content Server 输入验证错误漏洞 | |
| CVE-2019-13612 | MDaemon Technologies Email Server 输入验证错误漏洞 |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet