Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2024-39943 rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js). | https://github.com/truonghuuphuc/CVE-2024-39943-Poc | POC Details |
| 2 | None | https://github.com/A-little-dragon/CVE-2024-39943-Exploit | POC Details |
| 3 | None | https://github.com/JenmrR/Node.js-CVE-2024-39943 | POC Details |
| 4 | CVE-2024-39943 rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js). | https://github.com/Heyholiday067/CVE-2024-39943-Poc | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-39931 | 9.9 CRITICAL | Gogs 安全漏洞 |
| CVE-2024-39932 | 9.9 CRITICAL | Gogs 安全漏洞 |
| CVE-2024-39930 | 9.9 CRITICAL | Gogs 安全漏洞 |
| CVE-2024-39165 | 9.8 CRITICAL | Asial JpGraph 安全漏洞 |
| CVE-2024-39937 | 8.6 HIGH | Bluetron supOS 安全漏洞 |
| CVE-2024-39936 | 8.6 HIGH | Qt 安全漏洞 |
| CVE-2024-39934 | 7.8 HIGH | Robotmk 安全漏洞 |
| CVE-2024-39933 | 7.7 HIGH | Gogs 安全漏洞 |
| CVE-2024-22277 | 6.4 MEDIUM | VMware Cloud Director Availability 安全漏洞 |
| CVE-2024-39929 | Exim 安全漏洞 | |
| CVE-2024-39211 | Kaiten 安全漏洞 | |
| CVE-2024-39935 | Nginx Proxy Manager 安全漏洞 |
No comments yet