WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。Calls to Action是其中的一个活动召集插件。 WordPress Calls to Action插件2.4.3及之前版本中存在跨站脚本漏洞,该漏洞源于程序没有充分过滤用户提交的输入。当用户浏览受影响的网站时,其浏览器将执行攻击者提供的任意脚本代码。这可能导致攻击者窃取基于cookie的身份验证并发起其它攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Calls to Action plugin before 2.5.1 for WordPress contains stored XSS caused by unsanitized input in open-tab parameter in wp-admin/edit.php and wp-cta-variation-id parameter in ab-testing-call-to-action-example/, letting remote attackers inject arbitrary web script or HTML, exploit requires sending crafted requests. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2015/CVE-2015-8350.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2017-14302 | STDU Viewer 安全漏洞 | |
| CVE-2017-14303 | STDU Viewer 安全漏洞 | |
| CVE-2017-14239 | Dolibarr ERP/CRM 跨站脚本漏洞 | |
| CVE-2017-14305 | STDU Viewer 安全漏洞 | |
| CVE-2017-14306 | STDU Viewer 安全漏洞 | |
| CVE-2017-14304 | STDU Viewer 安全漏洞 | |
| CVE-2017-14301 | STDU Viewer 安全漏洞 | |
| CVE-2017-14300 | STDU Viewer 安全漏洞 | |
| CVE-2017-14299 | STDU Viewer 安全漏洞 | |
| CVE-2017-14298 | STDU Viewer 安全漏洞 | |
| CVE-2017-14307 | STDU Viewer 安全漏洞 | |
| CVE-2017-14308 | STDU Viewer 安全漏洞 | |
| CVE-2017-14309 | STDU Viewer 安全漏洞 | |
| CVE-2017-14310 | STDU Viewer 安全漏洞 | |
| CVE-2015-4523 | Blue Coat Malware Analysis Appliance和Malware Analyzer G2 安全漏洞 | |
| CVE-2015-7877 | Drupal User Dashboard模块SQL注入漏洞 | |
| CVE-2015-7879 | Drupal Stickynote模块跨站脚本漏洞 | |
| CVE-2017-14075 | Jungo WinDriver 安全漏洞 | |
| CVE-2017-14153 | Jungo WinDriver 安全漏洞 | |
| CVE-2017-14238 | Dolibarr ERP/CRM SQL注入漏洞 |
Showing top 20 of 80 CVEs. View all on vendor page → →
No comments yet