Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Apache Tomcat | Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56, 7.0.27 to 7.0.104 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Exploit for WebSocket Vulnerability in Apache Tomcat | https://github.com/RedTeamPentesting/CVE-2020-13935 | POC Details |
| 2 | None | https://github.com/aabbcc19191/CVE-2020-13935 | POC Details |
| 3 | Apache Tomcat versions 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56, and 7.0.27 to 7.0.104 contain a vulnerability in the WebSocket module where the payload length of WebSocket frames is not correctly validated. This can lead to an infinite loop when processing frames with invalid payload lengths. Attackers can exploit this flaw by sending multiple malicious requests, resulting in a denial of service (DoS) on the affected Tomcat instance. | https://github.com/projectdiscovery/nuclei-templates/blob/main/code/cves/2020/CVE-2020-13935.yaml | POC Details |
| 4 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Apache%20Tomcat%20WebSocket%20%E6%8B%92%E7%BB%9D%E6%9C%8D%E5%8A%A1%E6%BC%8F%E6%B4%9E%20CVE-2020-13935.md | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-15719 | OpenLDAP libldap 信任管理问题漏洞 | |
| CVE-2019-12773 | Verint Impact 跨站脚本漏洞 | |
| CVE-2019-12784 | Verint Impact 跨站请求伪造漏洞 | |
| CVE-2019-12783 | Verint Impact 输入验证错误漏洞 | |
| CVE-2020-11546 | SuperWebMailer 注入漏洞 | |
| CVE-2020-9297 | Netflix Titus 注入漏洞 | |
| CVE-2020-13846 | Singularity 安全漏洞 | |
| CVE-2020-15074 | OpenVPN 代码问题漏洞 | |
| CVE-2020-13845 | Sylabs Singularity 安全漏洞 | |
| CVE-2020-13847 | Sylabs Singularity 安全漏洞 | |
| CVE-2020-11827 | GOG Galaxy 安全漏洞 | |
| CVE-2020-13934 | Apache Tomcat 缓冲区错误漏洞 | |
| CVE-2020-15721 | RosarioSIS 跨站脚本漏洞 | |
| CVE-2020-15711 | MISP 跨站请求伪造漏洞 | |
| CVE-2020-15720 | Dogtag PKI 信任管理问题漏洞 | |
| CVE-2020-1948 | Apache Dubbo 代码问题漏洞 | |
| CVE-2020-13753 | WebKitGTK和WPE WebKit 输入验证错误漏洞 | |
| CVE-2020-11956 | Rittal PDU-3C002DEC和CMCIII-PU-9333E0FB 操作系统命令注入漏洞 | |
| CVE-2020-11955 | Rittal PDU-3C002DEC和CMCIII-PU-9333E0FB 安全漏洞 | |
| CVE-2020-11953 | Rittal PDU-3C002DEC和CMCIII-PU-9333E0FB 操作系统命令注入漏洞 |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet