高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| ベンダー | プロダクト | 影響を受けるバージョン | CPE | 購読 |
|---|---|---|---|---|
| Progress Software Corporation | WhatsUp Gold | 2023.1.0 ~ 2023.1.3 | - |
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|---|---|---|
| 1 | Exploit for CVE-2024-4885 | https://github.com/sinsinology/CVE-2024-4885 | POC詳細 |
| 2 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software WhatsUp Gold. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of GetFileWithoutZip method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the service account. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-4885.yaml | POC詳細 |
公開POCは見つかりませんでした。
ログインしてAI POCを生成| CVE-2024-4883 | 9.8 CRITICAL | WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability |
| CVE-2024-4884 | 9.8 CRITICAL | WhatsUp Gold CommunityController Unrestricted File Upload Remote Code Execution Vulnerabil |
| CVE-2024-5008 | 8.8 HIGH | WhatsUp Gold APM Unrestricted File Upload Remote Code Execution Vulnerability |
| CVE-2024-5012 | 8.6 HIGH | WhatsUp Gold Missing Authentication GetWindowsCredential Information Disclosure Vulnerabil |
| CVE-2024-5009 | 8.4 HIGH | WhatsUp Gold SetAdminPassword Improper Access Control Privilege Escalation Vulnerability |
| CVE-2024-5011 | 7.5 HIGH | WhatsUp Gold TestController Chart denial of service vulnerability |
| CVE-2024-5013 | 7.5 HIGH | WhatsUp Gold InstallController Denial-of-Service Vulnerability |
| CVE-2024-5010 | 7.5 HIGH | WhatsUp Gold TestController multiple information disclosure vulnerabilities |
| CVE-2024-5016 | 7.2 HIGH | WhatsUp Gold OnMessage Deserialization of Untrusted Data Remote Code Execution Vulnerabili |
| CVE-2024-5015 | 7.1 HIGH | WhatsUp Gold SessionControler Server-Side Request Forgery Information Disclosure Vulnerabi |
| CVE-2024-5014 | 7.1 HIGH | WhatsUp Gold GetASPReport Server-Side Request Forgery Information Disclosure |
| CVE-2024-5017 | 6.5 MEDIUM | WhatsUp Gold AppProfileImport path traversal vulnerability |
| CVE-2024-5019 | 5.3 MEDIUM | WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure Vulnerability |
| CVE-2024-5018 | 5.3 MEDIUM | WhatsUp Gold LoadUsingBasePath Directory Traversal Information Disclosure Vulnerability |
まだコメントはありません