Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Apache SkyWalking | Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2020-9483 OR CVE-2020-13921 | https://github.com/shanika04/apache_skywalking | POC Details |
| 2 | PoC of SQL Injection vul(CVE-2020-9483,Apache SkyWalking) | https://github.com/Neko-chanQwQ/CVE-2020-9483 | POC Details |
| 3 | When using H2/MySQL/TiDB as Apache SkyWalking storage and a metadata query through GraphQL protocol, there is a SQL injection vulnerability which allows access to unexpected data. Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0 H2/MySQL/TiDB storage implementations don't use the appropriate way to set SQL parameters. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-9483.yaml | POC Details |
| 4 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Apache%20SkyWalking%207.0.0%20graphql%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%20CVE-2020-9483.md | POC Details |
| 5 | None | https://github.com/tuaandatt/CVE-2020-9483---Apache-Skywalking-8.3.0 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-15049 | 9.9 CRITICAL | Squid 环境问题漏洞 |
| CVE-2020-14956 | Windows cleaning assistant 输入验证错误漏洞 | |
| CVE-2020-15395 | MediaArea MediaInfo 缓冲区错误漏洞 | |
| CVE-2017-18922 | LibVNCServer 缓冲区错误漏洞 | |
| CVE-2020-15396 | iFAX Solutions HylaFAX+和HylaFAX Enterprise 安全漏洞 | |
| CVE-2020-15397 | iFAX Solutions HylaFAX+和HylaFAX Enterprise 安全漏洞 | |
| CVE-2019-20893 | Activision Infinity Ward Call of Duty Modern Warfare 2 缓冲区错误漏洞 | |
| CVE-2020-15400 | CakePHP 跨站请求伪造漏洞 | |
| CVE-2020-15401 | IOBit Malware Fighter Pro 后置链接漏洞 | |
| CVE-2020-15411 | MISP 安全漏洞 | |
| CVE-2020-15412 | MISP 安全漏洞 | |
| CVE-2020-15415 | DrayTek Vigor3900、Vigor2960和Vigor300B 操作系统命令注入漏洞 | |
| CVE-2020-14947 | OCS Inventory NG 操作系统命令注入漏洞 | |
| CVE-2020-14957 | Windows cleaning assistant 输入验证错误漏洞 | |
| CVE-2020-13095 | Objective Development Software Little Snitch 后置链接漏洞 | |
| CVE-2020-14482 | Delta Electronics Industrial Automation DOPSoft 缓冲区错误漏洞 | |
| CVE-2020-15307 | Nozomi Networks Guardian 跨站脚本漏洞 | |
| CVE-2020-14474 | Cellebrite UFED 信任管理问题漏洞 | |
| CVE-2020-14059 | Squid 安全漏洞 | |
| CVE-2020-14058 | Squid 代码问题漏洞 |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet