Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | cve-2022-41352 poc | https://github.com/segfault-it/cve-2022-41352 | POC Details |
| 2 | Zimbra <9.0.0.p27 RCE | https://github.com/Cr4ckC4t/cve-2022-41352-zimbra-rce | POC Details |
| 3 | None | https://github.com/aryrz/cve-2022-41352-zimbra-rce | POC Details |
| 4 | None | https://github.com/lolminerxmrig/cve-2022-41352-zimbra-rce-1 | POC Details |
| 5 | None | https://github.com/qailanet/cve-2022-41352-zimbra-rce | POC Details |
| 6 | Zimbra Collaboration (ZCS) Arbitrary File Upload Vulnerability | https://github.com/rxerium/CVE-2022-41352 | POC Details |
| 7 | None | https://github.com/MuhammadWaseem29/cve-2022-41352 | POC Details |
| 8 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio. | https://github.com/projectdiscovery/nuclei-templates/blob/main/passive/cves/2022/CVE-2022-41352.yaml | POC Details |
| 9 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-41352.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-21169 | 7.3 HIGH | Prototype Pollution |
| CVE-2022-21797 | 7.3 HIGH | Arbitrary Code Execution |
| CVE-2022-40483 | Wedding Planner SQL注入漏洞 | |
| CVE-2022-41347 | Zimbra Collaboration Suite 安全漏洞 | |
| CVE-2022-38553 | Academy Learning Management System 跨站脚本漏洞 | |
| CVE-2022-36158 | Contec FLEXLAN FX3000和FX2000 安全漏洞 | |
| CVE-2022-36159 | Contec FLEXLAN FX3000和FX2000 信任管理问题漏洞 | |
| CVE-2022-38970 | ieGeek IG20 安全特征问题漏洞 | |
| CVE-2022-40924 | Zoo Management System 代码问题漏洞 | |
| CVE-2022-40925 | Zoo Management System 代码问题漏洞 | |
| CVE-2022-40928 | Online Leave Management System SQL注入漏洞 | |
| CVE-2022-40926 | Online Leave Management System SQL注入漏洞 | |
| CVE-2022-40927 | Online Leave Management System SQL注入漏洞 | |
| CVE-2022-40402 | Wedding Planner SQL注入漏洞 | |
| CVE-2022-40403 | Wedding Planner SQL注入漏洞 | |
| CVE-2022-40404 | Wedding Planner SQL注入漏洞 | |
| CVE-2022-40099 | Online Tours & Travels Management System SQL注入漏洞 | |
| CVE-2022-40484 | Wedding Planner SQL注入漏洞 | |
| CVE-2022-40485 | Wedding Planner SQL注入漏洞 | |
| CVE-2021-41437 | ASUS RT-AX88U 注入漏洞 |
Showing top 20 of 33 CVEs. View all on vendor page → →
No comments yet