PhpList是英国PhpList公司的一套开源的新闻通讯和电子邮件营销软件。 phplist 3.5.1存在安全漏洞,该漏洞源于应用程序不会检查插件 zip 文件中存储的任何文件扩展名。上传包含扩展名为 PHP、phtml、php7 的 php 文件的恶意插件将被复制到 plugins 目录,这将导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-27930 | 5.4 MEDIUM | IrisNext 跨站脚本漏洞 |
| CVE-2021-3598 | Industrial Light and Magic OpenEXR 缓冲区错误漏洞 | |
| CVE-2021-32559 | pywin32 输入验证错误漏洞 | |
| CVE-2021-35440 | smashing 跨站脚本漏洞 | |
| CVE-2021-34190 | Issabel PBX 跨站脚本漏洞 | |
| CVE-2020-22251 | PhpList 跨站脚本漏洞 | |
| CVE-2020-23697 | Monstra CMS 跨站脚本漏洞 |
No comments yet