Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Altenergy Power System Control Software set_timezone RCE Vulnerability (CVE-2023-28343) | https://github.com/gobysec/CVE-2023-28343 | POC Details |
| 2 | CVE-2023-28343 POC exploit | https://github.com/superzerosec/CVE-2023-28343 | POC Details |
| 3 | CVE-2023-28343 | https://github.com/hba343434/CVE-2023-28343 | POC Details |
| 4 | Altenergy Power Control Software C1.2.5 is susceptible to remote command injection via shell metacharacters in the index.php/management/set_timezone parameter, because of set_timezone in models/management_model.php. An attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized operations without entering necessary credentials. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-28343.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-1327 | NETGEAR RAX30 授权问题漏洞 | |
| CVE-2023-24180 | Libelfin 输入验证错误漏洞 | |
| CVE-2023-24279 | Open Networking Foundation ONOS 跨站脚本漏洞 | |
| CVE-2023-25206 | PrestaShop SQL注入漏洞 | |
| CVE-2023-26262 | Sitecore 代码问题漏洞 | |
| CVE-2023-26511 | Propius MachineSelector 信任管理问题漏洞 | |
| CVE-2023-27069 | TotalJS OpenPlatform 跨站脚本漏洞 | |
| CVE-2023-27070 | TotalJS OpenPlatform 跨站脚本漏洞 | |
| CVE-2023-27073 | Online Food Ordering System 跨站请求伪造漏洞 | |
| CVE-2023-27074 | BP Monitoring Management System SQL注入漏洞 | |
| CVE-2023-28144 | KDAB Hotspot 竞争条件问题漏洞 | |
| CVE-2023-28339 | Duncaen OpenDoas 安全漏洞 |
No comments yet