高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| ベンダー | プロダクト | 影響を受けるバージョン | CPE | 購読 |
|---|---|---|---|---|
| Unknown | WOOCS – Currency Switcher for WooCommerce. Professional and Free multi currency plugin – Pay in selected currency | 1.3.7.5 ~ 1.3.7.5 | - |
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|---|---|---|
| 1 | WordPress WOOCS plugin before 1.3.7.5 is susceptible to cross-site scripting. The plugin does not sanitize and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action, available to both unauthenticated and authenticated users, before outputting it back in the response. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0234.yaml | POC詳細 |
公開POCは見つかりませんでした。
ログインしてAI POCを生成| CVE-2021-4208 | ExportFeed <= 2.0.1.0 - Admin+ SQL Injection | |
| CVE-2022-0313 | Float Menu < 4.3.1 - Arbitrary Menu Deletion via CSRF | |
| CVE-2022-0288 | Ad Inserter < 2.7.10 - Reflected Cross-Site Scripting | |
| CVE-2022-0279 | AnyComment < 0.2.18 - Comment Rating Increase/Decrease via Race Condition | |
| CVE-2022-0255 | Database Backup for WordPress < 2.5.1 - Admin+ SQL Injection | |
| CVE-2022-0252 | Give < 2.17.3 - Reflected Cross-Site Scripting via Import Tool | |
| CVE-2022-0228 | Popup Builder < 4.0.7 - Admin+ SQL Injection | |
| CVE-2022-0211 | Shield Security < 13.0.6 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-0199 | Coming soon and Maintenance mode < 3.6.8 - Arbitrary Email Sending to Subscribed Users via | |
| CVE-2022-0186 | Image Photo Gallery Final Tiles Grid < 3.5.3 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2022-0164 | Coming soon and Maintenance mode < 3.6.7 - Subscriber+ Arbitrary Email Sending to Subscrib | |
| CVE-2022-0134 | AnyComment < 0.2.18 - Arbitrary HyperComments Import/Revert via CSRF | |
| CVE-2021-24921 | Advanced Database Cleaner < 3.0.4 - Reflected Cross-Site Scripting | |
| CVE-2021-25101 | Anti-Malware Security and Brute-Force Firewall < 4.20.94 - Admin+ Reflected Cross-Site Scr | |
| CVE-2021-25100 | Give < 2.17.3 - Reflected Cross-Site Scripting via Donation Forms Dashboard | |
| CVE-2021-25099 | Give < 2.17.3 - Unauthenticated Reflected Cross-Site Scripting | |
| CVE-2021-25082 | Popup Builder < 4.0.7 - LFI to RCE | |
| CVE-2021-25075 | Duplicate Page or Post < 1.5.1 - Arbitrary Settings Update to Stored XSS | |
| CVE-2021-25069 | WordPress Download Manager < 3.2.34 - Authenticated SQL Injection to Reflected XSS | |
| CVE-2021-25060 | Five Star Business Profile and Schema < 2.1.7 - Subscriber+ Page Creation & Settings Updat |
Showing 20 of 24 CVEs. View all on vendor page →
まだコメントはありません