Haraj是沙特阿拉伯Haraj公司的一个买卖平台。 Haraj 3.7 版本存在安全漏洞,该漏洞源于 User Upgrade Form 中存在反射型跨站脚本问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Haraj Script 3.7 - Reflected XSS | https://github.com/bigzooooz/CVE-2022-31299 | POC Details |
| 2 | Haraj 3.7 contains a cross-site scripting vulnerability in the User Upgrade Form. An attacker can inject malicious script and thus steal authentication credentials and launch other attacks. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31299.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-33295 | Joplin 跨站脚本漏洞 | |
| CVE-2018-18907 | D-Link DIR-850 授权问题漏洞 | |
| CVE-2022-30326 | TRENDnet TEW-831DR 跨站脚本漏洞 | |
| CVE-2022-30325 | TRENDnet TEW-831DR 安全漏洞 | |
| CVE-2022-26173 | JForum 跨站请求伪造漏洞 | |
| CVE-2021-36608 | webTareas 跨站脚本漏洞 | |
| CVE-2021-46820 | XOS-Shop xos_shop_system 安全漏洞 | |
| CVE-2021-37764 | XOS-Shop xos_shop_system 安全漏洞 | |
| CVE-2021-36609 | webTareas 跨站脚本漏洞 | |
| CVE-2020-28865 | PowerJob 安全漏洞 | |
| CVE-2020-25459 | WeBank Federated AI Technology Enabler 安全漏洞 | |
| CVE-2022-31295 | Online Discussion Forum Site 安全漏洞 | |
| CVE-2022-24562 | IOBit IOTransfer 访问控制错误漏洞 | |
| CVE-2020-35597 | Victor CMS SQL注入漏洞 | |
| CVE-2022-31464 | Adaware Protect 安全漏洞 | |
| CVE-2022-31294 | Sourcecodester Online Discussion Forum Site 跨站请求伪造漏洞 | |
| CVE-2022-29866 | OPC UA .NET Standard Stack 资源管理错误漏洞 | |
| CVE-2021-41487 | NOKIA VitalSuite SPM SQL注入漏洞 | |
| CVE-2022-31301 | Haraj 跨站脚本漏洞 | |
| CVE-2022-29863 | OPC UA .NET Standard Stack 安全漏洞 |
Showing top 20 of 65 CVEs. View all on vendor page → →
No comments yet