Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Sunhillo SureLine <8.7.0.1.1 is vulnerable to OS command injection. The /cgi/networkDiag.cgi script directly incorporated user-controllable parameters within a shell command, allowing an attacker to manipulate the resulting command by injecting valid OS command input. The following POST request injects a new command that instructs the server to establish a reverse TCP connection to another system, allowing the establishment of an interactive remote shell session. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-36380.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-31399 | 4.6 MEDIUM | 2N Access Unit 信任管理问题漏洞 |
| CVE-2020-18757 | MAC1100 PLC 安全漏洞 | |
| CVE-2021-21830 | AT&T Labs Xmill 缓冲区错误漏洞 | |
| CVE-2021-21812 | AT&T Labs Xmill 缓冲区错误漏洞 | |
| CVE-2020-21066 | Bento4 缓冲区错误漏洞 | |
| CVE-2021-21829 | AT&T Labs Xmill 缓冲区错误漏洞 | |
| CVE-2021-21814 | AT&T Labs Xmill 参数注入漏洞 | |
| CVE-2021-36788 | TYPO3 跨站脚本漏洞 | |
| CVE-2020-18759 | MAC1100 PLC 信息泄露漏洞 | |
| CVE-2020-18758 | MAC1100 PLC 命令注入漏洞 | |
| CVE-2021-36786 | TYPO3 信息泄露漏洞 | |
| CVE-2020-18756 | MAC1100 PLC 缓冲区错误漏洞 | |
| CVE-2020-18754 | MAC1100 PLC 信息泄露漏洞 | |
| CVE-2020-18753 | MAC1100 PLC 安全漏洞 | |
| CVE-2021-36792 | TYPO3 安全漏洞 | |
| CVE-2021-36791 | TYPO3 信息泄露漏洞 | |
| CVE-2021-36790 | TYPO3 跨站脚本漏洞 | |
| CVE-2021-36789 | TYPO3 SQL注入漏洞 | |
| CVE-2021-37028 | HG8045Q 操作系统命令注入漏洞 | |
| CVE-2021-38553 | Hashicorp HashiCorp Vault 安全特征问题漏洞 |
Showing top 20 of 57 CVEs. View all on vendor page → →
No comments yet