Fiyo CMS是一套用于制作CMS模板的内容管理系统(CMS)。 Fiyo CMS 2.0_1.9.1版本中存在SQL注入漏洞。远程攻击者可通过向apps/app_article/controller/rating.php文件发送‘id’参数或向user/login发送‘user’参数利用该漏洞执行任意SQL命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-16664 | Open Ticket Request System 代码注入漏洞 | |
| CVE-2017-16923 | 多款Shenzhen Tenda产品命令注入漏洞 | |
| CVE-2017-15044 | DocuWare Fulltext Search server 安全漏洞 | |
| CVE-2017-16613 | OpenStack Swauth 安全漏洞 | |
| CVE-2017-16920 | dayrui FineCms 安全漏洞 | |
| CVE-2017-16840 | FFmpeg VC-2 Video Compression解码器安全漏洞 | |
| CVE-2017-16919 | MapOS 跨站脚本漏洞 |
No comments yet