CVE-2024-44760
HIGHShenzhou News Union Enterprise Management System <18.8 - Incorrect Access Control
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-44760. PoCs published by WarmBrew.
AI-analyzed exploit summary The repository contains detailed technical writeups for multiple CVEs, including CVE-2024-44760, with descriptions, affected versions, and proof-of-concept code snippets. It provides insights into vulnerabilities like default credentials, XSS, SQL injection, and arbitrary file read/download issues.
Description
Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the server.
Exploits (1)
The repository contains detailed technical writeups for multiple CVEs, including CVE-2024-44760, with descriptions, affected versions, and proof-of-concept code snippets. It provides insights into vulnerabilities like default credentials, XSS, SQL injection, and arbitrary file read/download issues.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N