WordPress是WordPress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。Meta Box plugin是使用在其中的一个自定义字段插件。 WordPress Meta Box插件4.16.3之前版本中存在访问控制错误漏洞。该漏洞源于网络系统或产品未正确限制来自未授权角色的资源访问。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion in the ajax_delete_file function. The function accepts any attachment_id from the POST request and directly calls wp_delete_attachment() or unlink() without validating that the attachment belongs to the specified Meta Box field, without path traversal protection on the unlink path, and without any ownership or authorization checks. This makes it possible for authenticated attackers to delete arbitrary files on the server including wp-config.php. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-14793.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2019-14805 | UNA 跨站脚本漏洞 | |
| CVE-2019-14792 | WordPress WP Google Maps插件跨站脚本漏洞 | |
| CVE-2019-14234 | Django SQL注入漏洞 | |
| CVE-2019-14799 | WordPress FV Flowplayer Video Player插件跨站脚本漏洞 | |
| CVE-2019-14787 | WordPress Tribulant Newsletters插件跨站脚本漏洞 | |
| CVE-2019-14312 | Aptana Jaxer 路径遍历漏洞 | |
| CVE-2016-10865 | WordPress Lightbox Plus Colorbox插件跨站请求伪造漏洞 | |
| CVE-2019-14785 | WordPress CP Contact Form with PayPal插件跨站脚本漏洞 | |
| CVE-2019-14801 | WordPress FV Flowplayer Video Player插件 SQL注入漏洞 | |
| CVE-2019-14798 | WordPress 10Web Photo Gallery插件路径遍历漏洞 | |
| CVE-2019-14797 | WordPress 10Web Photo Gallery插件跨站脚本漏洞 | |
| CVE-2019-14796 | WordPress mq-woocommerce-products-price-bulk-edit插件跨站脚本漏洞 | |
| CVE-2019-14791 | WordPress Appointment Booking Calendar插件跨站脚本漏洞 | |
| CVE-2019-14794 | WordPress Meta Box插件代码问题漏洞 | |
| CVE-2019-14804 | UNA 跨站脚本漏洞 | |
| CVE-2019-14807 | MediaWiki MobileFrontend extension 跨站脚本漏洞 | |
| CVE-2019-14806 | Pallets Werkzeug 安全特征问题漏洞 | |
| CVE-2018-20858 | Recommender 跨站脚本漏洞 | |
| CVE-2017-18486 | Jitbit Software Helpdesk 安全特征问题漏洞 | |
| CVE-2019-12257 | Wind River Systems VxWorks 缓冲区错误漏洞 |
显示前 20 条,共 30 条。 查看全部 → →
暂无评论