phpBB是非常流行的WEB论坛程序。 phpBB的feed.php脚本没有正确地检查订阅源的权限,在以下环境中远程攻击者可以绕过权限检查执行非授权操作: 启用了订阅源 启用了张贴或主题源 * 非授权用户对私人论坛设置了论坛权限
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2010-1979 | Affiliate Datafeeds (com_datafeeds)目录遍历漏洞 | |
| CVE-2010-1985 | Six Apart Movable Type管理用户接口多个跨站脚本攻击漏洞 | |
| CVE-2010-1630 | phpBB 'posting.php'未明漏洞 | |
| CVE-2010-1629 | Phorum跨站脚本攻击漏洞 | |
| CVE-2010-1628 | Artifex Ghostscript无限递归调用远程代码执行漏洞 | |
| CVE-2010-1984 | Drupal Taxonomy Breadcrumb模块跨站脚本攻击漏洞 | |
| CVE-2010-1983 | Redcomponent redTWITTER目录遍历漏洞 | |
| CVE-2010-1982 | Joomlart JA Voice目录遍历漏洞 | |
| CVE-2010-1981 | Fabrikar Fabrik目录遍历漏洞 | |
| CVE-2010-1980 | Joomla!组件Joomla Flickr 'controller'参数本地文件包含漏洞 | |
| CVE-2010-1169 | PostgreSQL PL/perl存储过程安全限制绕过漏洞 | |
| CVE-2010-1978 | FreePHPBlogSoftware 'default_theme.php'远程文件包含漏洞 | |
| CVE-2010-1977 | Gohigheris J!WHMCS Integrator目录遍历漏洞 | |
| CVE-2010-1976 | Drupal Taxonomy Breadcrumb模块跨站脚本攻击漏洞 | |
| CVE-2010-1975 | PostgreSQL RESET ALL操作过程访问控制漏洞 | |
| CVE-2010-1454 | VMware SpringSource tc Server JMX接口绕过认证漏洞 | |
| CVE-2010-1447 | PostgreSQL PL/perl程序访问限制绕过漏洞 | |
| CVE-2010-1321 | MIT Kerberos GSS-API校验和空指针引用拒绝服务漏洞 | |
| CVE-2010-1170 | PostgreSQL PL/tcl存储过程绕过安全限制漏洞 |
No comments yet