Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | In CWP (Control Web Panel, previously CentOS Web Panel) before version 0.9.8.1107, an unauthenticated attacker can abuse null byte (%00) injection with the "scripts" parameter in the /user/loader.php or /user/login.php endpoints to register arbitrary API keys or access sensitive files. This can be exploited by using multiple %00 sequences to traverse directories via crafted requests such as /user/loader.php?api=1&scripts=.%00./.%00./api/account_new_create&acc=guadaapi, or similar payloads with more %00 instances (e.g., .%00%00%00./.%00%00%00./api/account_new_create). Attackers may use this flaw for arbitrary file access, privilege escalation, or remote code execution. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-45467.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-26964 | 7.4 HIGH | Devolutions Remote Desktop Manager 安全漏洞 |
| CVE-2022-4742 | 6.3 MEDIUM | json-pointer index.js set prototype pollution |
| CVE-2022-26969 | Directus 安全漏洞 | |
| CVE-2022-41767 | MediaWiki 安全漏洞 | |
| CVE-2022-41765 | MediaWiki 安全漏洞 | |
| CVE-2022-37309 | Open-Xchange OX App Suite 跨站脚本漏洞 | |
| CVE-2022-37312 | Open-Xchange OX App Suite 资源管理错误漏洞 | |
| CVE-2022-37311 | Open-Xchange OX App Suite 资源管理错误漏洞 | |
| CVE-2022-37310 | Open-Xchange OX App Suite 跨站脚本漏洞 | |
| CVE-2022-37313 | Open-Xchange OX App Suite 代码问题漏洞 | |
| CVE-2022-29852 | Open-Xchange OX App Suite跨站脚本漏洞 | |
| CVE-2021-44855 | MediaWiki 跨站脚本漏洞 | |
| CVE-2022-29853 | Open-Xchange OX App Suite 跨站脚本漏洞 | |
| CVE-2022-24120 | GE General Electric Renewable Energy MDS Radios 安全漏洞 | |
| CVE-2022-24119 | GE General Electric Renewable Energy MDS Radios 安全漏洞 | |
| CVE-2022-24118 | GE General Electric Renewable Energy MDS Radios 资源管理错误漏洞 | |
| CVE-2022-24117 | GE General Electric Renewable Energy MDS Radios 安全漏洞 | |
| CVE-2022-24116 | GE General Electric Renewable Energy MDS Radios 加密问题漏洞 | |
| CVE-2021-45466 | CWP Panel 代码注入漏洞 | |
| CVE-2021-44856 | MediaWiki 代码问题漏洞 |
Showing top 20 of 51 CVEs. View all on vendor page → →
No comments yet