WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。HMS Testimonials是其中的一个可在网页或帖子上显示客户评价的插件。 WordPress HMS Testimonials插件2.0.10及之前版本中存在跨站请求伪造漏洞。远程攻击者可利用该漏洞(1)通过hms-testimonials-addnew页面添加新的客户评价,(2)通过hms-testimonials-addnewgroup页面添加组,(3)
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2014-1311 | Apple Safari WebKit 缓冲区溢出漏洞 | |
| CVE-2014-2138 | Cisco Security Manager CRLF注入漏洞 | |
| CVE-2014-2137 | Cisco Web Security Appliance CRLF注入漏洞 | |
| CVE-2014-2125 | Cisco Unity Connection 跨站脚本漏洞 | |
| CVE-2014-1942 | Pearson eSIS Enterprise Student Information System 跨站脚本漏洞 | |
| CVE-2014-0901 | IBM WebSphere Portal 跨站脚本漏洞 | |
| CVE-2014-0828 | IBM WebSphere Portal Web Content Manager UI 跨站脚本漏洞 | |
| CVE-2013-3588 | Zyxel P660 拒绝服务漏洞 | |
| CVE-2014-2655 | Postfix Admin‘gen_show_status’函数SQL注入漏洞 | |
| CVE-2014-2578 | Splunk 跨站脚本漏洞 | |
| CVE-2014-2553 | Open Ticket Request System 跨站脚本漏洞 | |
| CVE-2013-5365 | Autodesk SketchBook 基于堆的缓冲区溢出漏洞 | |
| CVE-2013-3213 | Vtiger CRM SQL注入漏洞 | |
| CVE-2013-1770 | Ganglia Web ’view_name‘参数跨站脚本漏洞 | |
| CVE-2014-1313 | Apple Safari WebKit 缓冲区溢出漏洞 | |
| CVE-2014-1312 | Apple Safari WebKit 缓冲区溢出漏洞 | |
| CVE-2013-0735 | WordPress Mingle Forum插件SQL注入漏洞 | |
| CVE-2014-1310 | Apple Safari WebKit 缓冲区溢出漏洞 | |
| CVE-2014-1309 | Apple Safari WebKit 缓冲区溢出漏洞 | |
| CVE-2014-1308 | Apple Safari WebKit 缓冲区溢出漏洞 |
Showing top 20 of 33 CVEs. View all on vendor page → →
No comments yet