WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress的Shortcode Redirect中存在多个跨站脚本漏洞,该漏洞源于对用户提供的数据未经充分过滤。攻击者可利用该漏洞在受影响站点上下文的不知情用户浏览器上执行任意脚本代码,这可能有助于攻击者盗取基于cookie的认证证书进而发起其他攻击。Shortcode Redirect 1.0.01版本中存在该漏洞,其他版本中也可能存在该漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2012-5322 | Xavi 7968 ADSL Router 多个跨站脚本漏洞 | |
| CVE-2012-5328 | WordPress Mingle Forum插件多个SQL注入漏洞 | |
| CVE-2012-5331 | asaanCart 路径遍历漏洞 | |
| CVE-2012-5332 | at32 Reverse Proxy 拒绝服务漏洞 | |
| CVE-2012-5333 | Pre Printing Press SQL注入漏洞 | |
| CVE-2012-5334 | Pre Printing Press ‘pid’ 参数SQL注入漏洞 | |
| CVE-2012-5335 | Tiny Server 路径遍历漏洞 | |
| CVE-2012-5330 | asaanCart 多个跨站脚本漏洞 | |
| CVE-2012-0846 | Craig Knudsen WebCalendar ‘location’跨站脚本漏洞 | |
| CVE-2012-5323 | Xavi 跨站请求伪造漏洞 | |
| CVE-2012-5324 | Tracker Software PDF-XChange缓冲区溢出漏洞 | |
| CVE-2012-5321 | Tiki Wiki CMS Groupware ‘url’ 参数URI重定向漏洞 | |
| CVE-2012-5320 | Sagem 跨站请求伪造漏洞 | |
| CVE-2012-5319 | D-Link 跨站请求伪造漏洞 | |
| CVE-2012-1416 | SocialCMS 多个跨站请求伪造漏洞 | |
| CVE-2012-1308 | D-Link DSL-2640B ‘redpass.cgi’ 跨站请求伪造漏洞 | |
| CVE-2012-1189 | Open Racing Car Simulator/Speed Dreams 基于栈的缓冲区溢出漏洞 | |
| CVE-2011-5208 | WordPress BackWPup插件多个路径遍历漏洞 | |
| CVE-2011-4929 | Redmine 未明安全漏洞 | |
| CVE-2011-4928 | Redmine 跨站脚本漏洞 |
Showing top 20 of 50 CVEs. View all on vendor page → →
No comments yet