WordPress是Wordpress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是WordPress开源的一个应用插件。 WordPress 4.7.0版本之前的WooCommerce插件存在权限许可和访问控制问题漏洞,该漏洞允许远程攻击者通过order id参数查看任意订单的状态。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | woocommerce wordpress plugin - Affected Version: V 4.5.2 [CVE-2020-29156] | https://github.com/Ko-kn3t/CVE-2020-29156 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-35736 | Liftoff GateOne 路径遍历漏洞 | |
| CVE-2020-29250 | Cxuucms 跨站脚本漏洞 | |
| CVE-2020-29249 | Cxuucms 跨站脚本漏洞 | |
| CVE-2020-29299 | Zyxel ZLD和Zyxel SD-OS 命令注入漏洞 | |
| CVE-2020-29204 | XXL-JOB 跨站脚本漏洞 | |
| CVE-2020-35729 | KLog Server 操作系统命令注入漏洞 | |
| CVE-2020-35728 | FasterXML jackson-databind 代码问题漏洞 | |
| CVE-2020-35448 | GNU Binutils 缓冲区错误漏洞 | |
| CVE-2020-8290 | Backblaze 权限许可和访问控制问题漏洞 | |
| CVE-2020-8289 | Backblaze 信任管理问题漏洞 | |
| CVE-2020-35678 | Python 输入验证错误漏洞 |
No comments yet