bitrix.mpbuilder是一个能够使软件开发人员将创建的模块结构、语言选择等功能归档并发表在Marketplace上的模块。 Bitrix bitrix.mpbuilder模块1.0.12之前版本中存在目录遍历漏洞,该漏洞源于admin/bitrix.mpbuilder_step2.php脚本没有充分过滤‘work’数组参数的元素名。远程攻击者可借助目录遍历字符‘..’利用该漏洞包含并执行任意本地文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2015-5304 | Red Hat JBoss Enterprise Application Platform 拒绝服务漏洞 | |
| CVE-2015-7221 | Mozilla Firefox 缓冲区溢出漏洞 | |
| CVE-2015-7222 | Mozilla Firefox和Firefox ESR libstagefright 整数溢出漏洞 | |
| CVE-2015-7223 | Mozilla Firefox WebExtension APIs 安全漏洞 | |
| CVE-2015-6425 | Cisco Unified Communications Manager Identity Management子系统资源管理错误漏洞 | |
| CVE-2015-8000 | ISC BIND named 拒绝服务漏洞 | |
| CVE-2015-8461 | ISC BIND named 竞争条件漏洞 | |
| CVE-2015-8577 | McAfee VirusScan Enterprise Buffer Overflow Protection功能安全漏洞 | |
| CVE-2015-8578 | AVG Internet Security 安全漏洞 | |
| CVE-2015-8579 | Kaspersky Total Security 安全漏洞 | |
| CVE-2015-7220 | Mozilla Firefox 缓冲区溢出漏洞 | |
| CVE-2015-8357 | Bitrix bitrix.xscan模块目录遍历漏洞 | |
| CVE-2015-8476 | PHPMailer‘class.phpmailer.php’CRLF注入漏洞 | |
| CVE-2015-8562 | Joomla! Core 远程代码执行漏洞 | |
| CVE-2015-8563 | Joomla! com_templates组件跨站请求伪造漏洞 | |
| CVE-2015-8564 | Joomla! 目录遍历漏洞 | |
| CVE-2015-8565 | Joomla! 目录遍历漏洞 | |
| CVE-2015-8566 | Joomla! Framework Session程序包远程代码执行漏洞 | |
| CVE-2015-8580 | Foxit Reader和Foxit PhantomPDF 释放后重用漏洞 | |
| CVE-2015-7211 | Mozilla Firefox 输入验证漏洞 |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet