Wordpress e-Commerce Plugin 3.4版本及其早期版本的image_processing.php中存在无限制文件上传漏洞。远程攻击者可以借助上传一个具有可执行扩展名的文件并对wp-content/plugins/wp-shopping-cart/中的文件提交一个直接的请求来访问该文件,以执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-6809 | Bookingcentre Venalsur Booking Centre Hotels Group 'hotel_habitaciones.php' SQL注入漏洞 | |
| CVE-2008-6810 | bookingcentre booking_system_for_hotels_group SQL注入漏洞 | |
| CVE-2009-1657 | b2evolution Starrating Plugin SQL注入漏洞 | |
| CVE-2009-1658 | Realty Web-Base 'admin/admin.php' 多个SQL注入漏洞 | |
| CVE-2009-1659 | Intelliants eLitius 'admin/uploadimage.php'任意文件上传和权限绕过漏洞 | |
| CVE-2009-1660 | Urusoft URUWorks ViPlay3 '.vpl'文件远程缓冲区溢出漏洞 | |
| CVE-2009-1661 | Anoldman MicroTopic 'rating'参数SQL注入漏洞 | |
| CVE-2009-1662 | Recipe Script 'admin/index.php' 多个SQL注入漏洞 | |
| CVE-2009-1663 | Easy Scripts Answer and Question script 'myaccount.php'上传文件无限制及权限漏洞 | |
| CVE-2009-1664 | Easy Scripts Answer and Question Script 'myaccount.php'访问控制及权限漏洞 | |
| CVE-2009-1665 | Easy Scripts Answer and Question script 'myaccount.php'访问控制及权限漏洞 |
No comments yet