WikkaWiki 1.3.1和1.3.2版本中的actions/files/files.php中存在漏洞,该漏洞源于INTRANET_MODE启用时,支持文件上传,典型缺少从Apache HTTP Server TypesConfig文件的文件扩展。远程攻击者可利用该漏洞通过在放置此代码带有许多扩展名的文件如(1).mm或(2).vpp文件,执行任意PHP代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2011-4450 | WikkaWiki 路径遍历漏洞 | |
| CVE-2012-4392 | ownCloud ‘index.php’安全漏洞 | |
| CVE-2012-4393 | ownCloud 多个跨站请求伪造漏洞 | |
| CVE-2012-4394 | ownCloud ‘apps/files/js/filelist.js’ 跨站脚本漏洞 | |
| CVE-2012-4395 | ownCloud ‘index.php’跨站脚本漏洞 | |
| CVE-2012-4396 | ownCloud 多个跨站脚本漏洞 | |
| CVE-2012-4397 | ownCloud 多个跨站脚本漏洞 | |
| CVE-2012-4752 | ownCloud ‘appconfig.php’权限许可和访问控制漏洞 | |
| CVE-2012-4753 | ownCloud 多个跨站请求伪造漏洞 | |
| CVE-2011-4448 | WikkaWiki SQL注入漏洞 | |
| CVE-2012-4391 | ownCloud ‘core/ajax/appconfig.php’跨站请求伪造漏洞 | |
| CVE-2011-4451 | WikkaWiki多个安全漏洞 | |
| CVE-2011-4452 | WikkaWiki AdminUsers组件跨站请求伪造漏洞 | |
| CVE-2012-3012 | Arbiter Power Sentinel 拒绝服务漏洞 | |
| CVE-2012-2063 | Drupal ‘Slidebox’ 安全绕过漏洞 | |
| CVE-2012-2064 | Drupal ‘Views Language Switcher’跨站脚本漏洞 | |
| CVE-2012-2065 | Drupal ‘Language Icons’ 跨站脚本漏洞 | |
| CVE-2012-2066 | Drupal FCKeditor/CKEditor模块 跨站脚本漏洞 | |
| CVE-2012-2067 | Drupal 多个未明安全漏洞 | |
| CVE-2012-2068 | Drupal Fancy Slide模块 多个跨站脚本漏洞 |
Showing top 20 of 40 CVEs. View all on vendor page → →
No comments yet