WordPress是WordPress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。wp-google-maps plugin是使用在其中的一个Google地图插件。 WordPress wp-google-maps插件7.11.18之前版本中的includes/class.rest-api.php文件存在输入验证错误漏洞。该漏洞源于网络系统或产品未对输入的数据进行正确的验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Google Maps plugin before 7.11.18 contains a SQL injection vulnerability. The plugin includes /class.rest-api.php in the REST API and does not sanitize field names before a SELECT statement. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-10692.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2019-9759 | TONGDA Office Anywhere SQL注入漏洞 | |
| CVE-2018-15180 | QASymphony qTest Manager 输入验证错误漏洞 | |
| CVE-2019-9946 | Google Kubernetes 安全特征问题漏洞 | |
| CVE-2018-19275 | Mitel Networks InAttend和Mitel Networks CMG BluStar组件信任管理问题漏洞 | |
| CVE-2019-10707 | MKCMS SQL注入漏洞 | |
| CVE-2019-10708 | S-CMS SQL注入漏洞 | |
| CVE-2018-12679 | CoAPthon 代码问题漏洞 | |
| CVE-2018-12680 | CoAPthon 代码问题漏洞 | |
| CVE-2019-10714 | ImageMagick Studio ImageMagick 缓冲区错误漏洞 | |
| CVE-2019-6506 | SalesAgility SuiteCRM SQL注入漏洞 | |
| CVE-2018-18035 | OpenEMR 跨站脚本漏洞 |
No comments yet