WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。WP Content Source Control(wp-source-control)是其中的一个主题目录及帖子/网页的源代码管理插件。 WordPress WP Content Source Control (wp-source-control)插件3.0.0及之前版本的downloadfiles/download.php脚本中‘file_get_content
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | A directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Source Control (wp-source-control) plugin 3.0.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2014/CVE-2014-5368.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2014-5246 | Tenda A5s Router Cookie 身份验证绕过漏洞 | |
| CVE-2014-5274 | phpMyAdmin 跨站脚本漏洞 | |
| CVE-2014-5273 | phpMyAdmin 跨站脚本漏洞 | |
| CVE-2014-4767 | IBM WebSphere Application Server Liberty Profile 安全漏洞 | |
| CVE-2014-4764 | IBM WebSphere Application Server 安全漏洞 | |
| CVE-2014-3436 | Symantec Encryption Desktop和Symantec PGP Desktop 安全漏洞 | |
| CVE-2014-3089 | IBM Rational Directory Server和Rational Directory Administrator 安全漏洞 | |
| CVE-2014-3083 | IBM WebSphere Application Server 安全漏洞 | |
| CVE-2014-3070 | IBM WebSphere Application Server 安全漏洞 | |
| CVE-2014-3022 | IBM WebSphere Application Server 信息泄露漏洞 | |
| CVE-2014-0965 | IBM WebSphere Application Server 信息泄露漏洞 | |
| CVE-2014-5396 | Schrack Technik microControl 安全漏洞 | |
| CVE-2014-5338 | Mathias Kettner Check_MK multisite组件跨站脚本漏洞 | |
| CVE-2014-5262 | Cacti SQL注入漏洞 | |
| CVE-2014-5261 | Cacti 代码注入漏洞 | |
| CVE-2013-6306 | IBM Power 7 Systems 安全漏洞 | |
| CVE-2014-5149 | Xen 安全漏洞 | |
| CVE-2014-5146 | Xen 安全漏洞 | |
| CVE-2014-5122 | ESRI ArcGIS for Server 开放重定向漏洞 | |
| CVE-2014-5121 | ESRI ArcGIS for Server 跨站脚本漏洞 |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet