bitrix.xscan是一个可以在Bitrix内容管理系统(CMS)中检测木马的模块。 Bitrix bitrix.xscan模块1.0.4之前版本中存在目录遍历漏洞,该漏洞源于admin/bitrix.xscan_worker.php脚本没有充分过滤‘file’参数。远程攻击者可借助目录遍历字符‘..’利用该漏洞重命名任意文件,获取敏感信息或造成拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2015-5304 | Red Hat JBoss Enterprise Application Platform 拒绝服务漏洞 | |
| CVE-2015-7221 | Mozilla Firefox 缓冲区溢出漏洞 | |
| CVE-2015-7222 | Mozilla Firefox和Firefox ESR libstagefright 整数溢出漏洞 | |
| CVE-2015-7223 | Mozilla Firefox WebExtension APIs 安全漏洞 | |
| CVE-2015-6425 | Cisco Unified Communications Manager Identity Management子系统资源管理错误漏洞 | |
| CVE-2015-8000 | ISC BIND named 拒绝服务漏洞 | |
| CVE-2015-8461 | ISC BIND named 竞争条件漏洞 | |
| CVE-2015-8577 | McAfee VirusScan Enterprise Buffer Overflow Protection功能安全漏洞 | |
| CVE-2015-8578 | AVG Internet Security 安全漏洞 | |
| CVE-2015-8579 | Kaspersky Total Security 安全漏洞 | |
| CVE-2015-7220 | Mozilla Firefox 缓冲区溢出漏洞 | |
| CVE-2015-8358 | Bitrix bitrix.mpbuilder模块目录遍历漏洞 | |
| CVE-2015-8476 | PHPMailer‘class.phpmailer.php’CRLF注入漏洞 | |
| CVE-2015-8562 | Joomla! Core 远程代码执行漏洞 | |
| CVE-2015-8563 | Joomla! com_templates组件跨站请求伪造漏洞 | |
| CVE-2015-8564 | Joomla! 目录遍历漏洞 | |
| CVE-2015-8565 | Joomla! 目录遍历漏洞 | |
| CVE-2015-8566 | Joomla! Framework Session程序包远程代码执行漏洞 | |
| CVE-2015-8580 | Foxit Reader和Foxit PhantomPDF 释放后重用漏洞 | |
| CVE-2015-7211 | Mozilla Firefox 输入验证漏洞 |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet