Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | cve-2019-9194 | https://github.com/cved-sources/cve-2019-9194 | POC Details |
| 2 | elFinder before 2.1.48 has a command injection vulnerability in the PHP connector. The vulnerability occurs when performing image operations on JPEG files, where the filename is passed to the `exiftran` utility without proper sanitization, allowing command injection. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9194.yaml | POC Details |
| 3 | Command injection vulnerability in elFinder <= 2.1.47 via the PHP connector component. Allows unauthenticated remote code execution as the web server user. | https://github.com/estebanzarate/CVE-2019-9194-elFinder-Command-Injection-PoC | POC Details |
No public POC found.
Login to generate AI POC| CVE-2019-9201 | 9.8 CRITICAL | 多款Phoenix Contact产品访问控制错误漏洞 |
| CVE-2019-9200 | Poppler 缓冲区错误漏洞 | |
| CVE-2019-9195 | Grin 路径遍历漏洞 | |
| CVE-2019-7392 | CA Privileged Access Manager 授权问题漏洞 | |
| CVE-2019-9191 | ETSI Enterprise Transport Security 加密问题漏洞 | |
| CVE-2019-9192 | GNU C Library 资源管理错误漏洞 | |
| CVE-2019-9184 | Joomla! J2Store SQL注入漏洞 | |
| CVE-2019-9181 | SchoolCMS 安全漏洞 | |
| CVE-2019-9182 | ZZZCMS zzzphp 跨站请求伪造漏洞 | |
| CVE-2009-5155 | GNU C Library 代码问题漏洞 | |
| CVE-2018-20796 | GNU C Library 资源管理错误漏洞 | |
| CVE-2019-9169 | GNU C Library 缓冲区错误漏洞 | |
| CVE-2019-9168 | WordPress WooCommerce插件跨站脚本漏洞 | |
| CVE-2019-9199 | Sourceforge PoDoFo 代码问题漏洞 |
No comments yet