메뉴 건너뛰기

GREATUSER

cve

CVE-2017-16607

관리자 2018.01.25 04:00 조회 수 : 189

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within heapdumps.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download heap memory dump. An attacker can leverage this in conjunction with other vulnerabilities to disclose sensitive information in the context of the current process. Was ZDI-CAN-4718.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16607
번호 제목 글쓴이 날짜 조회 수
452 CVE-2018-6029 관리자 2018.01.25 137
451 CVE-2015-3257 관리자 2017.08.27 138
450 CVE-2014-7859 관리자 2017.08.27 138
449 CVE-2017-0079 관리자 2017.03.18 139
448 CVE-2017-16565 관리자 2017.11.09 139
447 CVE-2017-2912 관리자 2017.11.09 139
446 CVE-2018-5960 관리자 2018.01.25 139
445 CVE-2017-12809 (qemu) 관리자 2017.08.27 140
444 CVE-2017-14096 관리자 2018.01.25 140
443 CVE-2017-18045 관리자 2018.01.25 140
442 CVE-2017-15107 관리자 2018.01.25 140
441 CVE-2016-6992 관리자 2016.10.14 141
440 CVE-2017-0095 관리자 2017.03.18 141
439 CVE-2018-6001 관리자 2018.01.25 141
438 CVE-2014-3927 관리자 2017.04.04 142
위로