Joomla!是一套使用在Joomla!内容管理系统中的论坛组件。 远程攻击者可以通过向Groupware的多个模块提交恶意参数请求导致拒绝服务或执行任意代码。Groupware的论坛模块使用用户传送的参数来选择用户所要访问的论坛。由于没有正确地验证这个输入参数,如果远程攻击者向fmessagelist函数传送了空的或非数字的字符串,就会导致崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2009-2341 | Shalwan Opial index.php SQL注入漏洞 | |
| CVE-2009-2338 | FreeWebshop startmodules.inc.php 本地权限限制漏洞 | |
| CVE-2009-2337 | w3bcms Guestbook Module 'index.inc.php' SQL注入漏洞 | |
| CVE-2008-6853 | NetCat 'modules/poll/index.php' SQL注入漏洞 | |
| CVE-2008-6852 | Joomla! Ice Gallery Component 'index.php' SQL注入漏洞 | |
| CVE-2008-6851 | PHP Link Directory 'page.php' SQL注入漏洞 | |
| CVE-2008-6850 | PHP-Fusion 'messages.php'跨站脚本漏洞 | |
| CVE-2008-6849 | W2B phpGreetCards 'index.php' 任意文件上传漏洞 | |
| CVE-2008-6848 | W2B phpGreetCards 'index.php' 跨站脚本漏洞 | |
| CVE-2009-2345 | ClanSphere gbook module 多个SQL注入漏洞 | |
| CVE-2009-2344 | Sourcefire 3D Sensor和Defense Center user.cgi权限提升漏洞 | |
| CVE-2009-2343 | Zoph 'people.php' 跨站脚本漏洞 | |
| CVE-2009-2342 | Content Management Made Easy admin.php跨站脚本攻击漏洞 | |
| CVE-2008-0015 | Microsoft DirectShow MPEG2TuneRequest 组件栈溢出漏洞 | |
| CVE-2009-2340 | Opial damin/index.php SQL注入漏洞 | |
| CVE-2009-2339 | rentventory index.php SQL注入漏洞 | |
| CVE-2009-2359 | Yasinkaplan TekRADIUS SQL注入漏洞 | |
| CVE-2009-2358 | Yasinkaplan TekRADIUS安全权限漏洞 | |
| CVE-2009-2357 | Yasinkaplan TekRADIUS RADIUS安全权限漏洞 | |
| CVE-2009-2356 | NullLogic Groupware pgSQLQuery函数缓冲区溢出安全漏洞 |
Showing top 20 of 27 CVEs. View all on vendor page → →
No comments yet