Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。Social Stats是其中的一个带社交数据统计的搜索引擎模块。 Drupal Social Stats模块7.x-1.5之前版本的配置中存在跨站脚本漏洞。远程攻击者可利用该漏洞以‘[Content Type]: Create new content’权限注入任意Web脚本或HTML。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2014-5335 | Innovaphone PBX 跨站请求伪造漏洞 | |
| CVE-2014-5453 | Ubisoft Entertainment Ubisoft Uplay 权限许可和访问控制漏洞 | |
| CVE-2014-5454 | SAS Institute SAS Visual Analytics 任意文件上传漏洞 | |
| CVE-2014-5455 | OpenVPN Connect和Private Tunnel 代码问题漏洞 | |
| CVE-2014-5457 | QNAP Systems QNAP TS-469U 安全漏洞 | |
| CVE-2014-5458 | php-sqrl SQL注入漏洞 | |
| CVE-2014-2216 | Fortinet FortiOS 拒绝服务漏洞 | |
| CVE-2014-3589 | Python Image Library和Pillow 安全漏洞 | |
| CVE-2014-5251 | OpenStack Identity 权限许可和访问控制 | |
| CVE-2014-5252 | OpenStack Identity 权限许可和访问控制漏洞 | |
| CVE-2014-5253 | OpenStack Identity 安全漏洞 | |
| CVE-2014-5356 | OpenStack Image Registry and Delivery Service 安全漏洞 | |
| CVE-2014-0973 | Little Kernel bootloader 授权问题漏洞 | |
| CVE-2014-0974 | Little Kernel bootloader 权限许可和访问控制漏洞 | |
| CVE-2014-4325 | Little Kernel bootloader 授权问题漏洞 |
No comments yet