WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress中的MF Gig Calendar插件中存在漏洞,可被恶意人员利用进行跨站脚本攻击。该漏洞源于输入通过URL(当‘page_id’设置为Event Calendar页面时)返回给用户之前没有正确验证。攻击者可利用该漏漏洞在受影响站点上下文中用户浏览器会话中执行任意HTML和脚本代码。0.9.2版本中存在漏洞,其他版本也可能受到影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | A cross-site scripting vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar page. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2012/CVE-2012-4242.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2012-4427 | GNOME gnome-shell插件任意代码执行漏洞 | |
| CVE-2012-4450 | 389 Directory Server 访问绕过漏洞 | |
| CVE-2012-1588 | Drupal 文本过滤系统资源管理错误漏洞 | |
| CVE-2012-2240 | Debian devscripts ‘scripts/dscverify.pl’任意命令执行漏洞 | |
| CVE-2012-2241 | Debian devscripts ‘scripts/dget.pl’任意文件删除漏洞 | |
| CVE-2012-2242 | Debian devscripts ‘scripts/dget.pl’输入验证漏洞 | |
| CVE-2012-3500 | devscripts 任意文件修改漏洞 | |
| CVE-2012-4429 | Vino 信息泄露漏洞 | |
| CVE-2012-2153 | Drupal 权限许可和访问控制漏洞 | |
| CVE-2012-4432 | OptiPNG 释放后使用漏洞 | |
| CVE-2012-4437 | Smarty ‘SmartyException’类跨站脚本漏洞 | |
| CVE-2012-4415 | Guacamole libguac 缓冲区溢出漏洞 | |
| CVE-2012-4833 | IBM AIX/VIOS fuser 权限许可和访问控制问题漏洞 | |
| CVE-2012-4830 | IBM WebSphere Commerce 未明安全漏洞 | |
| CVE-2012-3319 | IBM Rational Business Developer 信息泄露漏洞 | |
| CVE-2012-3035 | Emerson DeltaV 缓冲区错误漏洞 | |
| CVE-2012-0748 | IBM Rational Team Concert 多个跨站请求伪造漏洞 | |
| CVE-2012-5232 | Joomla! ‘Quickl Form’ 组件未明跨站脚本漏洞 | |
| CVE-2012-5231 | miniCMS多个安全漏洞 | |
| CVE-2012-5230 | JE Story Submit 未明安全漏洞 |
Showing top 20 of 49 CVEs. View all on vendor page → →
No comments yet