Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-10184

EPSS 0.59% · P69
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-10184

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service; the issue does NOT affect YubiCloud.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Yubico YubiKey Validation Server SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Yubico YubiKey Validation Server是瑞典Yubico公司的一款身份认证服务器。 Yubico YubiKey Validation Server 2.40之前版本中存在SQL注入漏洞,该漏洞源于验证端点未检查SQL查询的长度。远程攻击者可利用该漏洞导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2020-10184

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-10184

登录查看更多情报信息。

Same Patch Batch · n/a · 2020-03-05 · 35 CVEs total

CVE-2020-10098Zammad 跨站脚本漏洞
CVE-2019-20501D-Link DWL-2600AP 操作系统命令注入漏洞
CVE-2019-20107TestLink SQL注入漏洞
CVE-2020-9380IPTV Smarters WEB TV PLAYER 代码问题漏洞
CVE-2020-10107PHPGurukul Daily Expense Tracker System 跨站脚本漏洞
CVE-2020-10106PHPGurukul Daily Expense Tracker System SQL注入漏洞
CVE-2020-9370HUMAX HGA12R-02 BRGCAA 授权问题漏洞
CVE-2020-10096Zammad 信息泄露漏洞
CVE-2020-10097Zammad 安全漏洞
CVE-2020-10173Comtrend VR-3033 操作系统命令注入漏洞
CVE-2020-10099Zammad 跨站脚本漏洞
CVE-2020-10100Zammad 信息泄露漏洞
CVE-2020-10101Zammad 输入验证错误漏洞
CVE-2020-10102Zammad 安全漏洞
CVE-2020-10103Zammad 跨站脚本漏洞
CVE-2020-10104Zammad 信息泄露漏洞
CVE-2020-10105Zammad 信息泄露漏洞
CVE-2019-17645Centreon 信息泄露漏洞
CVE-2020-6986Omron PLC CJ series 资源管理错误漏洞
CVE-2020-6971Emerson Electric ValveLink 访问控制错误漏洞

Showing top 20 of 35 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2020-10184

No comments yet


Leave a comment