The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NSangfor Next Gen Application Firewall
APPSangfor8.0.17
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Auth BypassFirewall
Referencje
Powiązane podatności
CVE-2023-30803CRITICAL9.8PL ✓ten sam produkt
Sangfor NGAF — ominięcie uwierzytelnienia przez nagłówek HTTP
CVE-2023-30805CRITICAL9.8PL ✓ten sam produkt
Sangfor NGAF — nieuwierzytelniony command injection w /LogInOut.php
CVE-2023-30806CRITICAL9.8PL ✓ten sam produkt
Sangfor NGAF — nieuwierzytelniony command injection przez cookie PHPSESSID
CVE-2023-30804MEDIUM4.9ten sam produkt
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure...
CVE-2026-1324HIGH7.4ten sam vendor
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected b...