Liferay Portal CE是一套开源企业网络平台。该平台用于构建公司运营、业务解决方案。 Liferay Portal CE 7.1.2 GA3版本中存在操作系统命令注入漏洞。该漏洞源于外部输入数据构造操作系统可执行命令过程中,网络系统或产品未正确过滤其中的特殊字符、命令等。攻击者可利用该漏洞执行非法操作系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-11456 | Gila CMS 跨站请求伪造漏洞 | |
| CVE-2019-11383 | Medha WiFi FTP Server application for Android 信任管理问题漏洞 | |
| CVE-2019-11384 | Zalora application for Android 信任管理问题漏洞 | |
| CVE-2019-5427 | c3p0 资源管理错误漏洞 | |
| CVE-2019-11461 | GNOME Nautilus 安全特征问题漏洞 | |
| CVE-2019-11460 | GNOME gnome-desktop 输入验证错误漏洞 | |
| CVE-2019-11459 | GNOME Evince 缓冲区错误漏洞 | |
| CVE-2019-9955 | 多款ZyXEL产品跨站脚本漏洞 | |
| CVE-2011-3151 | SELinux initscript misuse of touch | |
| CVE-2011-3147 | qcow format could expose host filesystem information | |
| CVE-2011-3145 | mount.ecrpytfs_private sets group owner of /etc/mtab to user's primary group | |
| CVE-2019-11445 | OpenKM 代码问题漏洞 | |
| CVE-2019-11455 | Tildeslash Monit 缓冲区错误漏洞 | |
| CVE-2019-11454 | Tildeslash Monit 跨站脚本漏洞 | |
| CVE-2019-11452 | whatsns SQL注入漏洞 | |
| CVE-2019-11451 | whatsns SQL注入漏洞 | |
| CVE-2019-11450 | whatsns SQL注入漏洞 | |
| CVE-2019-11449 | I,Librarian 跨站脚本漏洞 | |
| CVE-2019-11448 | ZOHO ManageEngine Applications Manager SQL注入漏洞 | |
| CVE-2019-11447 | 编号重复 |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet