WordPress是一款免费的论坛Blog系统。 WordPress的实现上存在输入验证漏洞,有管理员权限的远程攻击者可能利用此漏洞在服务器上执行任意命令。 当用户以管理器身份登录到WordPress后,就可以通过Write标签张贴标题、内容和上传文件。在Upload部分,用户可以向系统上传r57、c99等PHP脚本,所上传的脚本会出现在http://[target]/wp-content/uploads/[year]/[month]/file.php 。如果无法上传PHP脚本的话,会出现"File ty
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-1104 | Foxit Reader util.printf()函数远程栈溢出漏洞 | |
| CVE-2008-1660 | HP-UX 'useradd' 安全绕过漏洞 | |
| CVE-2008-1948 | GnuTLS 'lib/ext_server_name.c'堆溢出及拒绝服务漏洞 | |
| CVE-2008-1949 | GnuTLS 头文件'gnutls_kx.c'空指针引用及拒绝服务漏洞 | |
| CVE-2008-1950 | GnuTLS 头文件 'gnutls_cipher.c' 加密数据错误及拒绝服务漏洞 | |
| CVE-2008-2241 | CA ARCserve Backup caloggerd和xdr函数 路径遍历漏洞 | |
| CVE-2008-2242 | CA ARCserve Backup caloggerd和xdr函数 缓冲区错误漏洞 | |
| CVE-2008-2357 | mtr split.c文件远程栈溢出漏洞 | |
| CVE-2008-2390 | hp software_update 代码注入漏洞 | |
| CVE-2008-2391 | Codeplex Subsonic 输入验证漏洞 | |
| CVE-2008-2393 | EntertainmentScript 'play.php' SQL注入漏洞 | |
| CVE-2008-2394 | Tagworx Tagworx_cms 多个SQL注入漏洞 | |
| CVE-2008-2395 | AlkalinePHP 'thread.php' SQL注入漏洞 | |
| CVE-2008-2396 | microSSys CMS 'PAGES[$P]' 远程文件包含漏洞 | |
| CVE-2008-2397 | dotCMS 'search-results.dot' 跨站脚本攻击漏洞 | |
| CVE-2008-2398 | AppServ Open Project 'appservlang' Parameter 跨站脚本攻击漏洞 |
No comments yet