WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。Encrypted Contact Form是其中的一个使用端到端加密发送用户信息的插件。 WordPress Encrypted Contact Form插件1.1之前版本中存在跨站请求伪造漏洞,该漏洞源于wp-admin/options-general.php脚本没有充分过滤conformconf页面的Update Page操作中的‘iframe_url’参数。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2014-7872 | Comodo GeekBuddy 权限许可和访问控制漏洞 | |
| CVE-2015-4418 | ZOHO NetFlow Analyzer 安全漏洞 | |
| CVE-2015-2961 | ZOHO NetFlow Analyzer 跨站请求伪造漏洞 | |
| CVE-2015-2960 | ZOHO NetFlow Analyzer 跨站脚本漏洞 | |
| CVE-2015-2959 | ZOHO NetFlow Analyzer 安全漏洞 | |
| CVE-2014-9284 | 多款Buffalo路由器安全漏洞 | |
| CVE-2015-4427 | Ektron Content Management System 跨站脚本漏洞 | |
| CVE-2015-4335 | Redis 安全漏洞 | |
| CVE-2015-4109 | WordPress Users Ultra插件SQL注入漏洞 | |
| CVE-2015-4080 | Kankun Smart Socket设备和移动应用程序加密问题漏洞 | |
| CVE-2015-3648 | Montala Limited ResourceSpace 目录遍历漏洞 | |
| CVE-2015-3624 | Ektron Content Management System 跨站请求伪造漏洞 | |
| CVE-2015-3436 | Zarafa Collaboration Platform 后置链接漏洞 | |
| CVE-2015-2783 | PHP 安全漏洞 | |
| CVE-2015-3200 | Lighttpd mod_auth模块权限许可和访问控制问题漏洞 | |
| CVE-2015-4148 | PHP‘do_soap_call’函数输入验证漏洞 | |
| CVE-2015-4147 | PHP‘SoapClient's __call()’函数代码注入漏洞 | |
| CVE-2015-4026 | PHP pcntl_exec 安全漏洞 | |
| CVE-2015-4025 | PHP 权限许可和访问控制漏洞 | |
| CVE-2015-4024 | PHP‘multipart_buffer_headers’函数资源管理错误漏洞 |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet