dotCMS是美国dotCMS公司的一套内容管理系统(CMS)。该系统支持RSS订阅、博客、论坛等模块,并具有易于扩展和构建的特点。 dotCMS存在安全漏洞,该漏洞源于dotCMS不会清理临时文件名。攻击者利用该漏洞使用特制的请求,通过在dotCMS临时目录外写入的ContentResource API将文件发布到dotCMS。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | DotCMS management system contains an arbitrary file upload vulnerability via the /api/content/ path which can allow attackers to upload malicious Trojans to obtain server permissions. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-26352.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-7641 | 4.0 MEDIUM | Prototype Pollution |
| CVE-2022-27929 | Pexip Infinity 输入验证错误漏洞 | |
| CVE-2022-33903 | Tor 安全漏洞 | |
| CVE-2022-31213 | dbus-broker 代码问题漏洞 | |
| CVE-2020-16093 | LemonLDAP::NG 信任管理问题漏洞 | |
| CVE-2022-30550 | Dovecot 授权问题漏洞 | |
| CVE-2021-46784 | Squid 资源管理错误漏洞 | |
| CVE-2022-31212 | dbus-broker 缓冲区错误漏洞 | |
| CVE-2022-26656 | Pexip Infinity 安全漏洞 | |
| CVE-2022-26657 | Pexip Infinity 安全漏洞 | |
| CVE-2022-27928 | Pexip Infinity 安全漏洞 | |
| CVE-2022-26655 | Pexip Infinity 输入验证错误漏洞 | |
| CVE-2022-27930 | Pexip Infinity 输入验证错误漏洞 | |
| CVE-2022-27931 | Pexip Infinity 输入验证错误漏洞 | |
| CVE-2022-27932 | Pexip Infinity 输入验证错误漏洞 | |
| CVE-2022-27933 | Pexip Infinity 输入验证错误漏洞 | |
| CVE-2022-27934 | Pexip Infinity 输入验证错误漏洞 | |
| CVE-2022-27935 | Pexip Infinity 输入验证错误漏洞 | |
| CVE-2022-27936 | Pexip Infinity 输入验证错误漏洞 | |
| CVE-2022-27937 | Pexip Infinity 资源管理错误漏洞 |
Showing top 20 of 53 CVEs. View all on vendor page → →
No comments yet