Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software Corporation | WhatsUp Gold | 2023.1.0 ~ 2023.1.3 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Exploit for CVE-2024-4885 | https://github.com/sinsinology/CVE-2024-4885 | POC Details |
| 2 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software WhatsUp Gold. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of GetFileWithoutZip method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the service account. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-4885.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-4883 | 9.8 CRITICAL | WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability |
| CVE-2024-4884 | 9.8 CRITICAL | WhatsUp Gold CommunityController Unrestricted File Upload Remote Code Execution Vulnerabil |
| CVE-2024-5008 | 8.8 HIGH | WhatsUp Gold APM Unrestricted File Upload Remote Code Execution Vulnerability |
| CVE-2024-5012 | 8.6 HIGH | WhatsUp Gold Missing Authentication GetWindowsCredential Information Disclosure Vulnerabil |
| CVE-2024-5009 | 8.4 HIGH | WhatsUp Gold SetAdminPassword Improper Access Control Privilege Escalation Vulnerability |
| CVE-2024-5011 | 7.5 HIGH | WhatsUp Gold TestController Chart denial of service vulnerability |
| CVE-2024-5013 | 7.5 HIGH | WhatsUp Gold InstallController Denial-of-Service Vulnerability |
| CVE-2024-5010 | 7.5 HIGH | WhatsUp Gold TestController multiple information disclosure vulnerabilities |
| CVE-2024-5016 | 7.2 HIGH | WhatsUp Gold OnMessage Deserialization of Untrusted Data Remote Code Execution Vulnerabili |
| CVE-2024-5015 | 7.1 HIGH | WhatsUp Gold SessionControler Server-Side Request Forgery Information Disclosure Vulnerabi |
| CVE-2024-5014 | 7.1 HIGH | WhatsUp Gold GetASPReport Server-Side Request Forgery Information Disclosure |
| CVE-2024-5017 | 6.5 MEDIUM | WhatsUp Gold AppProfileImport path traversal vulnerability |
| CVE-2024-5019 | 5.3 MEDIUM | WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure Vulnerability |
| CVE-2024-5018 | 5.3 MEDIUM | WhatsUp Gold LoadUsingBasePath Directory Traversal Information Disclosure Vulnerability |
No comments yet