Mojarra是一款JavaServer Faces规范的实现。 Eclipse Mojarra 2.3.5之前版本中的ResourceManager.java文件的‘getLocalePrefix’函数存在安全漏洞。攻击者可借助‘loc’参数利用该漏洞从应用程序中下载配置文件或Java字节码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-14388 | joyplus-cms 跨站脚本漏洞 | |
| CVE-2018-0394 | Cisco Cloud Services Platform 2100 输入验证漏洞 | |
| CVE-2018-0396 | Cisco Unified Communications Manager IM and Presence Service Software 跨站脚本漏洞 | |
| CVE-2018-0398 | Cisco Finesse 安全漏洞 | |
| CVE-2018-0399 | Cisco Finesse 信息泄露漏洞 | |
| CVE-2018-0400 | Cisco Unified Contact Center Express 跨站脚本漏洞 | |
| CVE-2018-0401 | Cisco Unified Contact Center Express 跨站脚本漏洞 | |
| CVE-2018-0402 | Cisco Unified Contact Center Express 跨站请求伪造漏洞 | |
| CVE-2018-0403 | Cisco Unified Contact Center Express 信息泄露漏洞 | |
| CVE-2018-14364 | GitLab 安全漏洞 | |
| CVE-2018-14387 | WonderCMS 安全漏洞 | |
| CVE-2018-0393 | Cisco Policy Suite 安全漏洞 | |
| CVE-2018-14389 | joyplus-cms SQL注入漏洞 | |
| CVE-2018-12429 | JEESNS 跨站脚本漏洞 | |
| CVE-2018-14082 | PHP Scripts Mall JOB SITE 跨站脚本漏洞 | |
| CVE-2018-7546 | Kingsoft WPS Office 2016和Jinshan PDF 安全漏洞 | |
| CVE-2018-14380 | Graylog typeahead组件跨站脚本漏洞 | |
| CVE-2018-14381 | Pagekit 安全漏洞 | |
| CVE-2018-14382 | InstantSoft InstantCMS 跨站脚本漏洞 | |
| CVE-2018-2968 | Oracle Construction and Engineering Suite Primavera Unifier组件安全漏洞 |
Showing top 20 of 42 CVEs. View all on vendor page → →
No comments yet