MoinMoin 1.8.1之前的版本中的action/AttachFile.py存在多个跨站脚本攻击漏洞。远程攻击者可以借助一个对WikiSandBox组件的添加附件操作,注入任意的web脚本或HTML。该WikiSandBox组件带有 (1)重命名参数和(2)绘图参数(又称基地名变量)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-5958 | ActiveWebSoftwares Active Test 多个SQL注入漏洞 | |
| CVE-2009-0263 | Nullsoft Winamp MP3和AIFF文件解析堆溢出漏洞 | |
| CVE-2009-0262 | Triologic Media Player播放列表文件解析堆溢出漏洞 | |
| CVE-2009-0261 | effectmatrix total_video_player 缓冲区溢出漏洞 | |
| CVE-2008-5964 | ImpressCMS 'PHPSESSID' 会话固定漏洞 | |
| CVE-2008-5963 | Gravity GTD ’library/setup/rpc.php‘Eval注入漏洞 | |
| CVE-2008-5962 | Gravity GTD ‘library/setup/rpc.php’ 目录遍历漏洞 | |
| CVE-2008-5961 | Tribiq CMS 'index.php' 跨站脚本攻击漏洞 | |
| CVE-2008-5960 | Tribiq CMS 'index.php' SQL注入漏洞 | |
| CVE-2008-5959 | Active Test ’start.asp ‘SQL注入漏洞 | |
| CVE-2008-5948 | BNCwi 脚本index.php 目录遍历漏洞 | |
| CVE-2008-5957 | Mydyngallery SQL注入漏洞 | |
| CVE-2008-5956 | phpstreet webboard 权限许可和访问控制漏洞 | |
| CVE-2008-5955 | PHPSTREET Webboard 'show.php' SQL注入漏洞 | |
| CVE-2008-5954 | KTP Computer Customer Database 'lname' Parameter SQL注入漏洞 | |
| CVE-2008-5953 | KTP Computer Customer Database '目录遍历漏洞 | |
| CVE-2008-5952 | KTP Computer Customer Database SQL注入漏洞 | |
| CVE-2008-5951 | aspapps template_creature _nil_ 权限许可和访问控制漏洞 | |
| CVE-2008-5950 | ASPApps.com Template Creature 'media_level.asp' SQL注入漏洞 | |
| CVE-2008-5949 | tiddlywiki cctiddly PHP远程文件包含漏洞 |
No comments yet