WordPress是WordPress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。OneTone theme是使用在其中的一个响应式的网站主题插件。 WordPress OneTone theme 3.0.6及之前版本的includes/theme-functions.php文件存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-17231.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-11500 | Zoom Client for Meetings 加密问题漏洞 | |
| CVE-2020-11501 | GnuTLS 加密问题漏洞 | |
| CVE-2020-10960 | MediaWiki 安全漏洞 | |
| CVE-2019-17230 | WordPress OneTone theme 安全漏洞 | |
| CVE-2020-8637 | TestLink SQL注入漏洞 | |
| CVE-2020-8638 | TestLink SQL注入漏洞 | |
| CVE-2020-8639 | TestLink 代码问题漏洞 | |
| CVE-2020-8142 | Revive Adserver 安全漏洞 | |
| CVE-2020-8147 | npm package utils-extend 输入验证错误漏洞 | |
| CVE-2020-8143 | Revive Adserver 输入验证错误漏洞 |
No comments yet