Desdev DedeCMS(织梦内容管理系统)是中国卓卓网络(Desdev)公司的一套基于PHP的开源内容管理系统(CMS)。该系统具有内容发布、内容管理、内容编辑和内容检索等功能。 DedeCMS v5.7.101版本存在安全漏洞,该漏洞源于组件/dede/file_manage_control.php中存在任意文件上传漏洞。攻击者利用该漏洞通过特制的php文件执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-45461 | 7.5 HIGH | Veritas Technologies NetBackup 操作系统命令注入漏洞 |
| CVE-2022-42985 | 4.8 MEDIUM | MediaWiki 跨站脚本漏洞 |
| CVE-2022-44725 | OPC Foundation Local Discovery Server 安全漏洞 | |
| CVE-2022-44403 | Automotive Shop Management System SQL注入漏洞 | |
| CVE-2022-44402 | Automotive Shop Management System SQL注入漏洞 | |
| CVE-2022-44384 | rConfig 代码问题漏洞 | |
| CVE-2022-44001 | BACKCLICK 访问控制错误漏洞 | |
| CVE-2022-43332 | WonderCMS 跨站脚本漏洞 | |
| CVE-2022-43183 | XXL-JOB 代码问题漏洞 | |
| CVE-2022-43179 | Online Leave Management System SQL注入漏洞 | |
| CVE-2022-43171 | LIEF 缓冲区错误漏洞 | |
| CVE-2022-43163 | Online Diagnostic Lab Management System SQL注入漏洞 | |
| CVE-2022-43162 | Online Diagnostic Lab Management System SQL注入漏洞 | |
| CVE-2022-43142 | Password Storage Application 跨站脚本漏洞 | |
| CVE-2022-43140 | kkFileView 代码问题漏洞 | |
| CVE-2022-43138 | Dolibarr ERP/CRM 安全漏洞 | |
| CVE-2022-43096 | Mediatrix 4102 安全漏洞 | |
| CVE-2022-42982 | BKG Professional NtripCaster 访问控制错误漏洞 | |
| CVE-2022-38165 | F-Secure Policy Manager 安全漏洞 | |
| CVE-2021-31608 | Proofpoint Enterprise Protection 安全漏洞 |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet