XOOPS(eXtensible Object Oriented Portal System)是XOOPS团队开发维护的一套开源的基于PHP和MySQL的内容管理系统。该系统可用于创建各种网络社区。XOOPS Core是其中的一个核心存储库。 XOOPS Core 2.5.8版本中的/modules/profile/index.php文件存在安全漏洞。攻击者可利用该漏洞将用户重定向到其他网站。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | XOOPS Core 2.5.8 contains an open redirect vulnerability in /modules/profile/index.php due to the URL filter. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-12138.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2017-9769 | Razer Synapse rzpnk.sys驱动程序安全漏洞 | |
| CVE-2017-11494 | Popendorf Software Engineering SOL.Connect ISET-mpp meter SQL注入漏洞 | |
| CVE-2017-12140 | ImageMagick 资源管理错误漏洞 | |
| CVE-2017-12143 | libquicktime 安全漏洞 | |
| CVE-2017-12144 | ytnef 资源管理错误漏洞 | |
| CVE-2017-12145 | libquicktime 安全漏洞 | |
| CVE-2017-12199 | WordPress Etoile Ultimate Product Catalog插件SQL注入漏洞 | |
| CVE-2017-12200 | WordPress Etoile Ultimate Product Catalog插件Add Product Manually组件跨站脚本漏洞 | |
| CVE-2017-12142 | ytnef 安全漏洞 | |
| CVE-2017-9770 | Razer Synapse rzpnk.sys驱动程序安全漏洞 | |
| CVE-2017-11364 | Joomla! CMS安装程序安全漏洞 | |
| CVE-2017-9467 | Palo Alto Networks PAN-OS 跨站脚本漏洞 | |
| CVE-2017-9459 | Palo Alto Networks PAN-OS 跨站脚本漏洞 | |
| CVE-2017-9247 | 多款Lenovo产品Sierra Wireless WAN驱动程序权限许可和访问控制漏洞 | |
| CVE-2017-9244 | Trello app for iOS 跨站脚本漏洞 | |
| CVE-2017-8390 | Palo Alto Networks PAN-OS DNS Proxy 安全漏洞 | |
| CVE-2017-7890 | PHP GD Graphics Library 安全漏洞 | |
| CVE-2017-7642 | HashiCorp Vagrant VMware Fusion插件安全漏洞 | |
| CVE-2017-11438 | GitLab Community Edition和Enterprise Edition 安全漏洞 | |
| CVE-2017-11437 | GitLab Enterprise Edition 安全漏洞 |
Showing top 20 of 47 CVEs. View all on vendor page → →
No comments yet