DomainMod是一款基于PHP和MySQL的用于管理中心位置的域名和其它互联网资产的开源应用程序。 DomainMod 4.11.01及之前版本中的assets/add/account-owner.php页面存在跨站脚本漏洞。远程攻击者可借助‘Owner name’字段利用该漏洞注入任意的Web脚本或HTML。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | DomainMOD 4.11.01 contains a cross-site scripting vulnerability via assets/add/account-owner.php Owner name field. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-19749.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-18649 | GitLab 输入验证错误漏洞 | |
| CVE-2018-19527 | i4 assistant 跨站脚本漏洞 | |
| CVE-2018-19497 | The Sleuth Kit 安全漏洞 | |
| CVE-2018-19752 | DomainMod 跨站脚本漏洞 | |
| CVE-2018-19751 | DomainMod 跨站脚本漏洞 | |
| CVE-2018-19750 | DomainMod 跨站脚本漏洞 | |
| CVE-2018-18619 | Advanced Comment SQL注入漏洞 | |
| CVE-2018-19748 | SDCMS 路径遍历漏洞 | |
| CVE-2018-19120 | KDE kio-extras HTML Thumbnailer插件信息泄露漏洞 | |
| CVE-2018-15537 | OCS Inventory NG ocsreports 安全漏洞 | |
| CVE-2018-15978 | Adobe Flash Player 缓冲区错误漏洞 | |
| CVE-2018-19693 | tp5cms 跨站脚本漏洞 | |
| CVE-2018-19692 | tp5cms 安全漏洞 | |
| CVE-2018-11002 | Pulse Secure Desktop Client for Windows 安全漏洞 | |
| CVE-2018-19622 | Wireshark MMSE解析器安全漏洞 | |
| CVE-2018-19666 | OSSEC 路径遍历漏洞 | |
| CVE-2018-19664 | libjpeg-turbo 缓冲区错误漏洞 | |
| CVE-2018-19662 | libsndfile 缓冲区错误漏洞 | |
| CVE-2018-19661 | libsndfile 缓冲区错误漏洞 | |
| CVE-2018-19655 | dcraw 缓冲区错误漏洞 |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet