LyLme Spage(六零导航页)是中国六零(LyLme)开源的一个导航页面。致力于简洁高效无广告的上网导航和搜索入口,支持后台添加链接、自定义搜索引擎,沉淀最具价值链接,全站无商业推广,简约而不简单。 LyLme Spage v1.9.5 版本存在安全漏洞,该漏洞源于 get_head 函数存在服务器端请求伪造 (SSRF) 漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | LyLme spage v1.9.5 is vulnerable to server-side request forgery (SSRF) via the url parameter in apply/index.php. An attacker can force the server to make arbitrary requests, potentially accessing internal resources. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-36675.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-29152 | 5.9 MEDIUM | 多款Samsung产品 安全漏洞 |
| CVE-2024-36801 | SEMCMS 安全漏洞 | |
| CVE-2024-36800 | SEMCMS 安全漏洞 | |
| CVE-2024-36547 | idccms 安全漏洞 | |
| CVE-2024-36548 | idccms 安全漏洞 | |
| CVE-2024-36549 | idcCMS 安全漏洞 | |
| CVE-2024-36550 | idccms 安全漏洞 | |
| CVE-2024-36604 | Tenda O3 安全漏洞 | |
| CVE-2024-36857 | Jan 安全漏洞 | |
| CVE-2024-36858 | Jan 安全漏洞 | |
| CVE-2024-37273 | Jan 安全漏洞 | |
| CVE-2024-30889 | Audimex AG AudimexEE 安全漏洞 |
No comments yet