Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Apache Cocoon | Apache Cocoon 2.1.0 to 2.1.12 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Apache Cocoon 2.1.12 is susceptible to XML injection. When using the StreamGenerator, the code parses a user-provided XML. A specially crafted XML, including external system entities, can be used to access any file on the server system. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-11991.yaml | POC Details |
| 2 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Apache%20Cocoon%20XML%E6%B3%A8%E5%85%A5%20CVE-2020-11991.md | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-25253 | Hyland OnBase SQL注入漏洞 | |
| CVE-2019-20918 | InspIRCd 资源管理错误漏洞 | |
| CVE-2020-25269 | InspIRCd 资源管理错误漏洞 | |
| CVE-2020-25247 | Hyland OnBase 路径遍历漏洞 | |
| CVE-2020-25248 | Hyland OnBase 路径遍历漏洞 | |
| CVE-2020-25249 | Hyland OnBase 安全漏洞 | |
| CVE-2020-25250 | Hyland OnBase 安全漏洞 | |
| CVE-2020-25251 | Hyland OnBase 授权问题漏洞 | |
| CVE-2020-25252 | Hyland OnBase 跨站请求伪造漏洞 | |
| CVE-2019-20917 | InspIRCd 代码问题漏洞 | |
| CVE-2020-25254 | Hyland OnBase SQL注入漏洞 | |
| CVE-2020-25255 | Hyland OnBase 安全漏洞 | |
| CVE-2020-25256 | Hyland OnBase 信任管理问题漏洞 | |
| CVE-2020-25257 | Hyland OnBase 代码问题漏洞 | |
| CVE-2020-25258 | Hyland OnBase 代码问题漏洞 | |
| CVE-2020-25259 | Hyland OnBase 代码问题漏洞 | |
| CVE-2020-25260 | Hyland OnBase 代码问题漏洞 | |
| CVE-2020-25281 | LG mobile 安全漏洞 | |
| CVE-2020-24164 | Taoensso Nippy 代码问题漏洞 | |
| CVE-2020-15802 | Bluetooth Core 授权问题漏洞 |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet