whoogle-search是一个应用软件。自托管,没有广告,privacy-respecting元搜索引擎 whoogle-search 0.8.4 之前版本存在路径遍历漏洞,该漏洞源于app/routes.py 中的 config 函数不会验证用户控制的 name 变量和 config_data 变量,导致文件写入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| benbusby | whoogle-search | < 0.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-22205 | 9.1 CRITICAL | Whoogle Search Server Side Request Forgery vulnerability |
| CVE-2024-22203 | 9.1 CRITICAL | Whoogle Search Server Side Request Forgery vulnerability |
| CVE-2024-22417 | 6.1 MEDIUM | Whoogle Search Cross-site Scripting vulnerability |
No comments yet