SAP NetWeaver中的System Landscape Directory (SLD)组件的6.4 到 7.02版本中存在多个跨站脚本攻击漏洞。远程攻击者可以借助在(1) testsdic的action参数和(2) paramhelp.jsp的helpstring参数注入任意的web脚本和HTML。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2010-1452 | Apache HTTP Server多个远程拒绝服务漏洞 | |
| CVE-2010-2903 | Google Chrome未明漏洞 | |
| CVE-2010-2902 | Google Chrome SVG实现未明缓冲区错误漏洞 | |
| CVE-2010-2901 | Google Chrome渲染实现未明缓冲区错误漏洞 | |
| CVE-2010-2900 | Google Chrome 超大画布处理未明漏洞 | |
| CVE-2010-2899 | Google Chrome布局实施未明漏洞 | |
| CVE-2010-2898 | Google Chrome GNU C 库未明漏洞 | |
| CVE-2010-2897 | Google Chrome Windows内核未明漏洞 | |
| CVE-2010-2896 | IBM FileNet Content Manager权限许可和访问控制漏洞 | |
| CVE-2010-2905 | ScriptsFeed和BrotherScripts Scripts Directory 'info.php'SQL注入漏洞 | |
| CVE-2010-2912 | Kayako eSupport 'functions.php'SQL注入漏洞 | |
| CVE-2010-2911 | Kayako eSupport 'index.php'newsid参数SQL注入漏洞 | |
| CVE-2010-2910 | Joomla! Ozio Gallery组件SQL注入漏洞 | |
| CVE-2010-2909 | Toughtomato TTVideo组件 'ttvideo.php'SQL注入漏洞 | |
| CVE-2010-2908 | Joomdle组件SQL注入漏洞 | |
| CVE-2010-2907 | Huru Helpdesk组件SQL注入漏洞 | |
| CVE-2010-2906 | ScriptsFeed 和BrotherScripts Scripts Directory 'articlesdetails.php'SQL注入漏洞 |
No comments yet