WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress easy-wp-smtp plugin 1.4.4之前版本存在日志信息泄露漏洞,该漏洞源于允许接管管理员帐户,如果攻击者可以列出wp-content/plugins/easy-wp-smtp/目录,则他们可以 发现包含所有密码重置链接的日志文件(例如,#######_ debug_log.txt)。 攻击者可以请
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The WordPress Easy WP SMTP Plugin has its log folder remotely accessible and its content available for access. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-35234.yaml | POC Details |
| 2 | Detected WordPress Easy WP SMTP plugin debug log file exposed via directory listing, potentially revealing sensitive email contents including password reset links. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/wordpress/wp-easy-wp-smtp-log-exposure.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-0444 | Google Android Pixel 安全漏洞 | |
| CVE-2020-35457 | GNOME Glib 输入验证错误漏洞 | |
| CVE-2020-0457 | Google Android 缓冲区错误漏洞 | |
| CVE-2020-0016 | Google Android Pixel 信任管理问题漏洞 | |
| CVE-2020-0456 | Google Android 缓冲区错误漏洞 | |
| CVE-2020-0455 | Google Android Pixel 缓冲区错误漏洞 | |
| CVE-2020-0019 | Google Android Pixel 信任管理问题漏洞 | |
| CVE-2020-0458 | Google Android Pixel 输入验证错误漏洞 | |
| CVE-2020-0459 | Google Android 安全漏洞 | |
| CVE-2020-0468 | Google Android Pixel 安全漏洞 | |
| CVE-2020-0440 | Google Android 安全漏洞 | |
| CVE-2020-0464 | Google Android 安全漏洞 | |
| CVE-2020-0466 | Google Android资源管理错误漏洞 | |
| CVE-2020-0099 | Google Android 安全漏洞 | |
| CVE-2020-20189 | Ornose15 Newpk SQL注入漏洞 | |
| CVE-2020-14368 | Eclipse Che 跨站请求伪造漏洞 | |
| CVE-2020-20184 | Liftoff GateOne 输入验证错误漏洞 | |
| CVE-2020-29304 | WordPress 跨站脚本漏洞 | |
| CVE-2020-29303 | WordPress SabaiApps DirectoriesPro plugin 跨站脚本漏洞 | |
| CVE-2020-20183 | Zyxel P1302-T10 代码问题漏洞 |
Showing top 20 of 56 CVEs. View all on vendor page → →
No comments yet