Desdev DedeCMS(织梦内容管理系统)是中国卓卓网络(Desdev)公司的一套基于PHP的开源内容管理系统(CMS)。该系统具有内容发布、内容管理、内容编辑和内容检索等功能。 DedeCMS 5.7.109版本存在安全漏洞,该漏洞源于允许远程攻击者通过精心设计的对 /dede/tpl.php 的 POST 请求来运行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-35791 | 6.1 MEDIUM | Vound Intella Connect 输入验证错误漏洞 |
| CVE-2023-35792 | 5.4 MEDIUM | Vound Intella Connect 跨站脚本漏洞 |
| CVE-2023-37771 | Art Gallery Management System SQL注入漏洞 | |
| CVE-2023-33534 | Guanzhou Tozed Kangwei Intelligent Technology ZLTS10G 跨站请求伪造漏洞 | |
| CVE-2021-31681 | yolov5-face 代码问题漏洞 | |
| CVE-2021-31680 | yolov5-face 代码问题漏洞 | |
| CVE-2021-31651 | NeoFrag 跨站脚本漏洞 | |
| CVE-2020-21881 | DuxCMS 跨站请求伪造漏洞 | |
| CVE-2020-21662 | Yunyecms SQL注入漏洞 | |
| CVE-2023-38750 | Zimbra Collaboration Suite 安全漏洞 | |
| CVE-2023-34644 | Ruijie Networks Product 代码注入漏洞 | |
| CVE-2023-37580 | Zimbra Collaboration Suite 跨站脚本漏洞 | |
| CVE-2023-34917 | Fuge CMS 输入验证错误漏洞 | |
| CVE-2023-34916 | Fuge CMS 输入验证错误漏洞 | |
| CVE-2020-36763 | DuxCMS 跨站脚本漏洞 | |
| CVE-2023-3983 | Advantech iView SQL注入漏洞 | |
| CVE-2023-38989 | jeesite 安全漏洞 | |
| CVE-2022-42183 | Precisely Spectrum Spatial Analyst 代码问题漏洞 | |
| CVE-2022-42182 | Precisely Spectrum Spatial Analyst 路径遍历漏洞 | |
| CVE-2023-39122 | BMC Control-M SQL注入漏洞 |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet