DeShang DSMall是中国德尚(DeShang)公司的一个多用户商城系统。 DeShang DSMall 5.0.3 版本之前存在安全漏洞,该漏洞源于文件 application/home/controller/MemberAuth.php 对参数 file_name 的操作导致路径遍历。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-0415 | 6.3 MEDIUM | DeShang DSMall Image URL TaobaoExport.php access control |
| CVE-2024-0417 | 5.4 MEDIUM | DeShang DSShop MemberAuth.php path traversal |
| CVE-2024-0411 | 5.3 MEDIUM | DeShang DSMall HTTP GET Request install.php access control |
| CVE-2024-0412 | 5.3 MEDIUM | DeShang DSShop HTTP GET Request install.php access control |
| CVE-2024-0413 | 5.3 MEDIUM | DeShang DSKMS install.php access control |
| CVE-2024-0414 | 5.3 MEDIUM | DeShang DSCMS install.php access control |
No comments yet