WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。Site Editor plugin是使用在其中的一个所见即所得的前端编辑器。 WordPress Site Editor插件1.1.1及之前版本中存在本地文件包含漏洞。远程攻击者可通过向editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php文件发送‘ajax_path’参数利用该漏洞检索任
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Wordpress plugin Site-Editor v1.1.1 LFI exploit | https://github.com/0x00-0x00/CVE-2018-7422 | POC详情 |
| 2 | Site Editor WordPress Plugin <= 1.1.1 Local File Inclusion Script | https://github.com/jessisec/CVE-2018-7422 | POC详情 |
| 3 | Local File Inclusion in WordPress Plugin Site Editor 1.1.1 | https://github.com/JacobEbben/CVE-2018-7422 | POC详情 |
| 4 | WordPress Site Editor through 1.1.1 allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-7422.yaml | POC详情 |
| 5 | Exploit for CVE-2018-7422: Local File Inclusion in WordPress Plugin Site Editor 1.1.1 [T1574.008] | https://github.com/ndr-repo/CVE-2018-7422 | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2014-2652 | Unify OpenScape Deployment Service SQL注入漏洞 | |
| CVE-2018-7445 | MikroTik RouterOS SMB service 缓冲区错误漏洞 | |
| CVE-2018-7262 | Red Hat Ceph radosgw 安全漏洞 | |
| CVE-2018-5233 | Grav CMS 跨站脚本漏洞 | |
| CVE-2014-5450 | Zarafa Collaboration Platform 信息泄露漏洞 | |
| CVE-2014-5443 | Seafile Server和Server Professional Edition 权限许可和访问控制漏洞 | |
| CVE-2014-2885 | TrueCrypt 数字错误漏洞 | |
| CVE-2014-2884 | TrueCrypt 安全漏洞 | |
| CVE-2014-2675 | WordPress WP HTML Sitemap插件跨站请求伪造漏洞 | |
| CVE-2014-2674 | WordPress Ajax Pagination(twitter Style)插件路径遍历漏洞 | |
| CVE-2017-18240 | Gentoo app-admin/collectd包安全漏洞 | |
| CVE-2014-2550 | WordPress Disable Comments插件跨站请求伪造漏洞 | |
| CVE-2014-2297 | WordPress VideoWhisper Live Streaming Integration插件跨站脚本漏洞 | |
| CVE-2014-2274 | WordPress Subscribe To Comments Reloaded插件跨站请求伪造漏洞 | |
| CVE-2014-4024 | 多款F5 Networks产品信息泄露漏洞 | |
| CVE-2018-8732 | WampServer 跨站脚本漏洞 | |
| CVE-2018-8761 | Yxcms building system(compatible cell phone)安全漏洞 | |
| CVE-2018-6843 | Kentico SQL注入漏洞 | |
| CVE-2018-6842 | Kentico 跨站脚本漏洞 |
暂无评论