dwbooster Booking Calendar Contact Form是dwbooster个人开发者的一款用于网站预约管理的表单插件。 dwbooster Booking Calendar Contact Form 1.0.23版本存在SQL注入漏洞,该漏洞源于短代码功能未对calendar参数进行清理和转义,导致容易受到SQL注入攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dwbooster | Booking Calendar Contact Form | ≤ 1.0.23 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dwbooster | Booking Calendar Contact Form | 0 ~ 1.0.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2016-20068 | 8.2 HIGH | WordPress Booking Calendar Contact Form 1.0.23 SQL Injection |
| CVE-2016-20066 | 7.2 HIGH | WordPress CP Polls 1.0.8 Persistent Cross-Site Scripting |
| CVE-2016-20084 | 7.2 HIGH | WordPress appointment-booking-calendar 1.1.24 Privilege Escalation XSS |
| CVE-2016-20070 | 6.4 MEDIUM | WordPress Booking Calendar Contact Form 1.0.23 Privilege Escalation Stored XSS |
| CVE-2016-20067 | 4.3 MEDIUM | WordPress CP Polls 1.0.8 Cross-Site Request Forgery |
No comments yet