DeShang DSShop是中国德尚(DeShang)公司的一款单店铺移动商城网店系统。 DeShang DSShop 2.1.5 版本之前存在安全漏洞,该漏洞源于文件 application/home/controller/MemberAuth.php 对参数 member_info 的操作导致路径遍历。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-0415 | 6.3 MEDIUM | DeShang DSMall Image URL TaobaoExport.php access control |
| CVE-2024-0416 | 5.4 MEDIUM | DeShang DSMall MemberAuth.php path traversal |
| CVE-2024-0411 | 5.3 MEDIUM | DeShang DSMall HTTP GET Request install.php access control |
| CVE-2024-0412 | 5.3 MEDIUM | DeShang DSShop HTTP GET Request install.php access control |
| CVE-2024-0413 | 5.3 MEDIUM | DeShang DSKMS install.php access control |
| CVE-2024-0414 | 5.3 MEDIUM | DeShang DSCMS install.php access control |
No comments yet