WikkiTikkiTavi是一个脚本引擎,能运行在Wiki网站上的PHP脚本。WikkiTikkiTavi 1.11版本的upload.php中存在无限制文件上传漏洞。远程攻击者可以借助上传一个具有可执行扩展名的文件并对img/的文件提交一个直接请求来访问该文件,以执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-6147 | AspApp ForumApp 'data/8690.mdb和data/8690BAK.mdb'权限许可和访问控制漏洞 | |
| CVE-2009-0598 | PhpMesFilms 'index.php' SQL注入漏洞 | |
| CVE-2009-0597 | W3B_Cms 'admin/index.php' SQL注入漏洞 | |
| CVE-2009-0596 | phpSkelSite 'skysilver/login.tpl.php'目录遍历漏洞 | |
| CVE-2009-0595 | phpSkelSite 'skysilver/login.tpl.php'远程注入漏洞 | |
| CVE-2009-0594 | Apmuthu phpSkelSite 'index.php'跨站脚本攻击漏洞 | |
| CVE-2009-0593 | plxWebDev plx Autoreminder 'members.php' SQL注入漏洞 | |
| CVE-2009-0592 | PNphpBB2 参数ModName 多个目录遍历漏洞 | |
| CVE-2008-6153 | Jayeshp Pixel8 Web Photo Album 'Photo.asp' SQL注入漏洞 | |
| CVE-2008-6152 | SepCity Faculty Portal 'deptdisplay.asp' SQL注入漏洞 | |
| CVE-2008-6151 | SepCity Shopping Mall 'shpdetails.asp' SQL注入漏洞 | |
| CVE-2008-6150 | SepCity Classified Ads 'classdis.asp' SQL注入漏洞 | |
| CVE-2008-6149 | Joomlaapps mDigg'category'参数SQL注入漏洞 | |
| CVE-2008-6148 | Raven-Worx LiveTicker 'tid'参数SQL注入漏洞 | |
| CVE-2009-0599 | Wireshark 程序wiretap/netscreen.c缓冲区溢出和拒绝服务攻击漏洞 | |
| CVE-2008-6146 | DeluxeBB 'pm.php'delete*参数SQL注入漏洞 | |
| CVE-2008-6145 | TYPO3 WEC Discussion Forum (wec_discussion) extension SQL注入漏洞 | |
| CVE-2008-6144 | TYPO3 WEC Discussion Forum (wec_discussion) extension 跨站脚本攻击漏洞 | |
| CVE-2008-6143 | Owentechkenya Owen Technologies OwenPoll Cookie权限绕过漏洞 | |
| CVE-2008-6142 | China-On-Site FlexPHPic 'admin/index.php' SQL注入漏洞 |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet