WRTeam eShop是印度WRTeam公司的一个电子商务网站。 WRTeam eShop 3.0.4版本存在安全漏洞,该漏洞源于攻击者利用json搜索解析和json响应的跨站脚本漏洞通过get_products?search参数注入任意web脚本或利用HTML。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | eShop 3.0.4 contains a reflected cross-site scripting vulnerability in json search parse and json response in wrteam.in. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-35493.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-35487 | Zammad 安全漏洞 | |
| CVE-2022-35488 | Zammad 资源管理错误漏洞 | |
| CVE-2022-35489 | Zammad 安全漏洞 | |
| CVE-2022-35490 | Zammad 安全漏洞 | |
| CVE-2022-36267 | Airspan AirSpot 5410 安全漏洞 | |
| CVE-2022-36266 | Airspan AirSpot 5410 跨站脚本漏洞 | |
| CVE-2022-36265 | Airspan AirSpot 5410 安全漏洞 | |
| CVE-2022-36264 | Airspan AirSpot 5410 代码问题漏洞 | |
| CVE-2022-34293 | Wolfssl 安全漏洞 | |
| CVE-2021-41615 | Embedthis Software GoAhead 安全特征问题漏洞 |
No comments yet