PoC-in-GitHub/2022/CVE-2022-29554.json

33 lines
1.6 KiB
JSON
Raw Permalink Normal View History

2024-11-28 19:31:51 +01:00
[
{
"id": 490736695,
"name": "printix-CVE-2022-29554",
"full_name": "ComparedArray\/printix-CVE-2022-29554",
"owner": {
"login": "ComparedArray",
"id": 45703484,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/45703484?v=4",
"html_url": "https:\/\/github.com\/ComparedArray",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/ComparedArray\/printix-CVE-2022-29554",
"description": "A \"Mishandling of Input to API\" or \"Exposed Dangerous Method or Function\" vulnerability in PrintixService.exe, in Kofax Printix's \"Printix Secure Cloud Print Management\", Version 1.3.1156.0 and below allows a Local Or Remote attacker the ability to attack any enterprise installation running in KioskMode by exploiting the local PrintixProxy class to invoke an error with localhost\/e\/?error=INVALID_CREDENTIAL&errorMessage={kioskModeValue}. When an attacker combines this with CVE-2022-29552, the attacker may change the ProgramDir registry value to invoke any program named unis000.exe.",
"fork": false,
"created_at": "2022-05-10T14:37:19Z",
"updated_at": "2022-07-12T06:10:45Z",
"pushed_at": "2022-07-09T20:15:55Z",
"stargazers_count": 3,
"watchers_count": 3,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 3,
"score": 0,
"subscribers_count": 3
}
]