Batflat是Batflat的一个免费的轻量级、快速和简单的 CMS。 Batflat 1.3.6中存在注入漏洞,该漏洞源于外部输入数据构造代码段的过程中,网络系统或产品未正确过滤其中的特殊元素。攻击者可利用该漏洞生成非法的代码段,修改网络系统或组件的预期的执行控制流。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-23337 | 7.2 HIGH | Command Injection |
| CVE-2021-23338 | 6.6 MEDIUM | Deserialization of Untrusted Data |
| CVE-2021-23336 | 5.9 MEDIUM | Web Cache Poisoning |
| CVE-2020-28500 | 5.3 MEDIUM | Regular Expression Denial of Service (ReDoS) |
| CVE-2020-22427 | Nagios XI 代码注入漏洞 | |
| CVE-2021-26822 | Teachers Record Management System SQL注入漏洞 | |
| CVE-2021-26201 | CASAP Automated Enrollment SQL注入漏洞 | |
| CVE-2021-26200 | SourceCodester user area for Library System SQL注入漏洞 | |
| CVE-2021-3239 | Sourcecodester Pisay Online E-Learning System SQL注入漏洞 | |
| CVE-2020-29143 | OpenEMR SQL注入漏洞 | |
| CVE-2020-29139 | OpenEMR SQL注入漏洞 | |
| CVE-2020-29140 | OpenEMR SQL注入漏洞 | |
| CVE-2020-29142 | OpenEMR SQL注入漏洞 | |
| CVE-2020-28337 | Microweber 路径遍历漏洞 | |
| CVE-2021-27211 | Steghide 安全漏洞 | |
| CVE-2021-27201 | Endian Firewall Community 操作系统命令注入漏洞 | |
| CVE-2021-3375 | Atomi ActivePresenter 缓冲区错误漏洞 | |
| CVE-2020-24899 | Nagios XI和Nagios 命令注入漏洞 | |
| CVE-2021-25296 | Nagios XI 安全漏洞 | |
| CVE-2020-22425 | Centreon SQL注入漏洞 |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet