WonderCMS是一套基于PHP的开源内容管理系统(CMS)。 WonderCMS 3.1.3 存在代码问题漏洞,该漏洞源于index.php的addCustomThemePluginRepository函数的服务器端请求伪造(SSRF),允许远程攻击者可利用该漏洞通过一个精心制作的主题插件安装程序URL执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-35314 | WonderCMS 操作系统命令注入漏洞 | |
| CVE-2021-30464 | OMICRON StationGuard 资源管理错误漏洞 | |
| CVE-2020-14105 | Xiaomi 10 安全漏洞 | |
| CVE-2021-28156 | Hashicorp HashiCorp Consul 安全漏洞 | |
| CVE-2020-25864 | HashiCorp Consul and Consul Enterprise 跨站脚本漏洞 | |
| CVE-2021-28492 | unisys stealth(core) 安全漏洞 | |
| CVE-2021-28793 | Lex Li vscode-restructuredtext 访问控制错误漏洞 | |
| CVE-2021-25681 | ADTRAN AdTran-Personal-Phone-Manager-Vulns 安全漏洞 | |
| CVE-2021-25680 | ADTRAN AdTran-Personal-Phone-Manager-Vulns 跨站脚本漏洞 | |
| CVE-2021-25679 | ADTRAN AdTran-Personal-Phone-Manager-Vulns 跨站脚本漏洞 | |
| CVE-2021-29155 | Linux kernel 缓冲区错误漏洞 | |
| CVE-2021-30496 | Telegram 安全漏洞 |
No comments yet