WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。Blogstand Banner(blogstand-smart-banner)是其中的一个横幅插件。 WordPress Blogstand Banner (blogstand-smart-banner)插件1.0版本中存在跨站脚本漏洞,该漏洞源于wp-admin/options-general.php脚本没有充分过滤‘bs_blog_id’参数。远程攻击者可利用
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2014-4846 | WordPress Meta Slider插件跨站脚本漏洞 | |
| CVE-2014-4698 | PHP SPL组件释放后重用漏洞 | |
| CVE-2014-4670 | PHP SPL组件释放后重用漏洞 | |
| CVE-2014-3888 | 多款Yokogawa产品基于栈的缓冲区溢出漏洞 | |
| CVE-2014-3318 | Cisco Unified Communications Manager DNA组件输入验证漏洞 | |
| CVE-2014-3316 | Cisco Unified Communications Manager DNA组件输入验证漏洞 | |
| CVE-2014-3315 | Cisco Unified Communications Manager DNA组件跨站脚本漏洞 | |
| CVE-2014-3311 | Cisco WebEx Meetings Server和WebEx Meeting Center 基于栈的缓冲区溢出漏洞 | |
| CVE-2014-3310 | Cisco WebEx Meetings Server和WebEx Meeting Center 输入验证漏洞 | |
| CVE-2014-2963 | Liferay Portal 跨站脚本漏洞 | |
| CVE-2014-4847 | WordPress Random Banner插件跨站脚本漏洞 | |
| CVE-2014-4845 | WordPress BannerMan插件跨站脚本漏洞 | |
| CVE-2014-4856 | WordPress Polldaddy Polls & Ratings插件跨站脚本漏洞 | |
| CVE-2014-4855 | WordPress Polylang插件跨站脚本漏洞 | |
| CVE-2014-4854 | WordPress WP Construction Mode插件跨站脚本漏洞 | |
| CVE-2014-4853 | OpenDocMan 跨站脚本漏洞 | |
| CVE-2014-4852 | Digital Craft AtomCMS SQL注入漏洞 | |
| CVE-2014-4851 | FoeCMS 开放重定向漏洞 | |
| CVE-2014-4850 | FoeCMS SQL注入漏洞 | |
| CVE-2014-4849 | FoeCMS 跨站脚本漏洞 |
No comments yet