WBCE CMS是一套基于PHP和MySQL的开源内容管理系统(CMS)。 WBCE CMS v1.5.4版本存在安全漏洞,该漏洞源于/admin/settings/save.php中存在跨站点脚本(XSS)漏洞。攻击者利用该漏洞通过注入Website Footer字段的特制有效载荷来执行任意web脚本或HTML。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-45038.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-45210 | JeecgBoot Jeecg-Boot SQL注入漏洞 | |
| CVE-2022-45036 | WBCE CMS 跨站脚本漏洞 | |
| CVE-2022-45037 | WBCE CMS 跨站脚本漏洞 | |
| CVE-2022-45039 | WBCE CMS 代码问题漏洞 | |
| CVE-2022-45040 | WBCE CMS 跨站脚本漏洞 | |
| CVE-2022-45152 | Moodle 代码问题漏洞 | |
| CVE-2022-45205 | JeecgBoot Jeecg-Boot SQL注入漏洞 | |
| CVE-2022-45206 | JeecgBoot Jeecg-Boot SQL注入漏洞 | |
| CVE-2022-45207 | JeecgBoot Jeecg-Boot SQL注入漏洞 | |
| CVE-2022-45208 | JeecgBoot Jeecg-Boot SQL注入漏洞 | |
| CVE-2022-44860 | Automotive Shop Management System SQL注入漏洞 | |
| CVE-2022-45218 | Human Resource Management System 跨站脚本漏洞 | |
| CVE-2022-45225 | Book Store Management System 跨站脚本漏洞 | |
| CVE-2022-45475 | Tiny File Manager 安全漏洞 | |
| CVE-2022-45476 | Tiny File Manager 代码问题漏洞 | |
| CVE-2022-45884 | Linux kernel 资源管理错误漏洞 | |
| CVE-2022-45885 | Linux kernel 资源管理错误漏洞 | |
| CVE-2022-45886 | Linux kernel 资源管理错误漏洞 | |
| CVE-2022-45887 | Linux kernel 安全漏洞 | |
| CVE-2022-45888 | Linux kernel 资源管理错误漏洞 |
Showing top 20 of 40 CVEs. View all on vendor page → →
No comments yet