Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerabilities in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note that this product has not been supported since 2018 and should be removed or replaced. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/other/dixell-xweb500-filewrite.yaml | POC Details |
| 2 | Emerson Dixell XWEB-500 contains an arbitrary file write caused by unauthenticated access to /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi, letting attackers write any file on the system, exploit requires no authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-45420.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-45310 | Sangoma Technologies Corporation Switchvox 信息泄露漏洞 | |
| CVE-2021-45346 | SQLite 安全漏洞 | |
| CVE-2022-24110 | Kiteworks MFT 安全漏洞 | |
| CVE-2021-45421 | Emerson Dixell XWEB-500 信息泄露漏洞 | |
| CVE-2022-24686 | Hashicorp Nomad 竞争条件问题漏洞 | |
| CVE-2021-46371 | AntD Admin 访问控制错误漏洞 | |
| CVE-2021-45392 | Tenda Router AX12 缓冲区错误漏洞 | |
| CVE-2022-22854 | Sourcecodester Hospital Patient Records Management System安全漏洞 | |
| CVE-2022-23367 | Fulusso 跨站脚本漏洞 | |
| CVE-2021-45347 | zzcms 授权问题漏洞 | |
| CVE-2022-25150 | Malwarebytes 安全漏洞 | |
| CVE-2022-24988 | galois_2p8 安全漏洞 | |
| CVE-2021-45348 | Attendance Management System 安全漏洞 | |
| CVE-2021-43106 | Compass Plus e-Commerce Payment Gateway 安全漏洞 | |
| CVE-2019-16864 | Enterprise Distributed Technologies CompleteFTP Server 命令注入漏洞 | |
| CVE-2019-25057 | R3 Corda 安全漏洞 | |
| CVE-2021-46463 | NGINX 安全漏洞 | |
| CVE-2022-22295 | Metinfo MetInfo SQL注入漏洞 | |
| CVE-2022-23335 | Metinfo MetInfo SQL注入漏洞 | |
| CVE-2022-23336 | S-CMS SQL注入漏洞 |
Showing top 20 of 32 CVEs. View all on vendor page → →
No comments yet