Lionwiki是Lionwiki团队的一个使用Php编写的基于文件模板的小型wiki建站系统。 LionWiki 3.2.12之前版本存在安全漏洞,该漏洞允许未经身份验证的用户通过在index.php f1变量(即本地文件包含)中创建字符串,以web服务器用户的身份读取文件。注意:此漏洞仅影响维护者不再支持的产品。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted strings in the index.php f1 variable, aka local file inclusion. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-27191.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-28649 | 8.8 HIGH | WordPress 跨站请求伪造漏洞 |
| CVE-2020-7773 | 6.5 MEDIUM | Cross-site Scripting (XSS) |
| CVE-2020-28650 | 6.4 MEDIUM | WordPress 跨站脚本漏洞 |
| CVE-2020-7765 | 5.6 MEDIUM | Prototype Pollution |
| CVE-2020-27988 | Nagios XI 跨站脚本漏洞 | |
| CVE-2020-27486 | Garmin Forerunner 235 缓冲区漏洞 | |
| CVE-2020-28693 | HorizontCMS 代码问题漏洞 | |
| CVE-2020-27485 | Garmin Forerunner 235 输入验证错误漏洞 | |
| CVE-2020-27990 | Nagios XI 跨站脚本漏洞 | |
| CVE-2020-27989 | Nagios XI 跨站脚本漏洞 | |
| CVE-2020-27622 | JetBrains IntelliJ IDEA 安全漏洞 | |
| CVE-2020-28723 | Cloudavid Pparam 资源管理错误漏洞 | |
| CVE-2020-27422 | Anuko Time Tracker 代码问题漏洞 | |
| CVE-2020-27423 | Anuko Time Tracker 安全漏洞 | |
| CVE-2020-25952 | Phpgurukul User Registration Login Management System SQL注入漏洞 | |
| CVE-2020-13773 | Ivanti Endpoint Manager 跨站脚本漏洞 | |
| CVE-2020-13769 | Ivanti Endpoint Manager SQL注入漏洞 | |
| CVE-2020-13772 | Ivanti Endpoint Manager 安全漏洞 | |
| CVE-2020-27623 | JetBrains IdeaVim 安全漏洞 | |
| CVE-2020-27628 | JetBrains TeamCity 安全漏洞 |
Showing top 20 of 54 CVEs. View all on vendor page → →
No comments yet