This Living Local php script是一个成员信息管理工具,可以实现对成员信息自动分类的存储到数据库中,并做为一个独立的网站使用。 eZoneScripts Living Local 1.1版本的editimage.php中存在无限制文件上传漏洞。远程认证管理员通过上传一个具有可执行扩展名的文件执行任意PHP代码并提交一个直接的请求来访问此上传文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-6528 | Tmax Soft JEUS Alternate Data Stream 源代码信息泄露漏洞 | |
| CVE-2009-1148 | phpMyAdmin BLOB Streaming 多个输入验证漏洞 | |
| CVE-2009-1149 | phpMyAdmin BLOB Streaming 多个输入验证漏洞 | |
| CVE-2009-1150 | phpMyAdmin 'export page' 跨站脚本攻击漏洞 | |
| CVE-2009-1151 | phpMyAdmin setup.php脚本PHP代码注入漏洞 | |
| CVE-2009-1152 | Siemens Gigaset SE461 WiMAX路由器远程拒绝服务漏洞 | |
| CVE-2008-6529 | eZoneScripts Living Local 'listtest.php' 跨站脚本攻击漏洞 | |
| CVE-2008-6531 | Atlassian JIRA 远程安全绕过漏洞 | |
| CVE-2008-6532 | Drupal跨站请求伪造漏洞 | |
| CVE-2008-6533 | Drupal Deleted Input Format 跨站脚本攻击漏洞 | |
| CVE-2008-6534 | Vwsolutions Null FTP Server 'SITE'命令任意指令注入漏洞 | |
| CVE-2008-6535 | PayPal eStores 'admin/settings.php'权限许可和访问控制漏洞 |
No comments yet