Incomcms是Incomcms个人开发者的一个建站系统。 IncomCMS 2.0版本存在安全漏洞,该漏洞源于modules/uploader/showcase/script.php 不安全文件上传漏洞。此漏洞允许未经身份验证的攻击者可利用该漏洞将文件上传到服务器。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | IncomCMS 2.0 has a an insecure file upload vulnerability in modules/uploader/showcase/script.php. This allows unauthenticated attackers to upload files into the server. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-29597.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-29599 | Imagemagick Studio ImageMagick 安全漏洞 | |
| CVE-2020-28727 | SeedDMS 跨站脚本漏洞 | |
| CVE-2020-5799 | Eat Spray Love mobile app 安全漏洞 | |
| CVE-2020-5800 | Eat Spray Love mobile app 安全漏洞 | |
| CVE-2020-5798 | Druva inSync Client installer 安全漏洞 | |
| CVE-2020-27151 | Kata Containers 安全漏洞 | |
| CVE-2020-26513 | Intland codeBeamer ALM 安全漏洞 | |
| CVE-2020-26122 | Inspur NF5266M5 数据伪造问题漏洞 | |
| CVE-2020-29595 | ACDSee Photo Studio Studio Professional 安全漏洞 | |
| CVE-2020-29600 | Eldy Awstats 路径遍历漏洞 |
No comments yet