WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。Oturia Smart Google Code Inserter plugin是使用在其中的一个元标记验证添加插件。 WordPress Oturia Smart Google Code Inserter插件3.5之前的版本中存在身份验证绕过漏洞。该漏洞源于smartgooglecode.php文件的‘saveGoogleCode()’函数没有检测当前请求是否来自
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/lucad93/CVE-2018-3810 | POC Details |
| 2 | cve-2018-3810 | https://github.com/cved-sources/cve-2018-3810 | POC Details |
| 3 | Exploit for CVE-2018-3810 | https://github.com/nth347/CVE-2018-3810_exploit | POC Details |
| 4 | Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-3810.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-3813 | FLIR Brickstream 2300 访问控制错误漏洞 | |
| CVE-2018-3814 | Craft CMS 代码问题漏洞 | |
| CVE-2017-18008 | ImageMagick 安全漏洞 | |
| CVE-2017-18009 | OpenCV 缓冲区错误漏洞 | |
| CVE-2017-18010 | WordPress E-goi Smart Marketing SMS and Newsletters Forms插件跨站脚本漏洞 | |
| CVE-2017-18011 | Genie Affiliate Ads for Clickbank Products插件跨站脚本漏洞 | |
| CVE-2017-18012 | WordPress Z-URL Preview插件跨站脚本漏洞 | |
| CVE-2017-18013 | Silicon Graphics LibTIFF 安全漏洞 | |
| CVE-2018-3811 | WordPress Oturia Smart Google Code Inserter插件SQL注入漏洞 | |
| CVE-2017-18006 | Celartem Extensis Portfolio NetPublish 跨站脚本漏洞 |
No comments yet