云记-渗透云记 - 专注于网络安全与技术分享-第750页
CVE-2022-0149: WooCommerce Stored Exporter WordPress Plugin < 2.7.1 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2022-0149: WooCommerce Stored Exporter WordPress Plugin < 2.7.1 - Cross-Site Scripting

漏洞标题 CVE-2022-0149: WooCommerce Stored Exporter WordPress Plugin < 2.7.1 - Cross-Site Scripting 漏洞描述 The plugin was affected by a reflected cross-site scripting vulnerab...
CVE-2005-2428: Lotus Domino R5 and R6 WebMail - Information Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2005-2428: Lotus Domino R5 and R6 WebMail – Information Disclosure

漏洞标题 CVE-2005-2428: Lotus Domino R5 and R6 WebMail - Information Disclosure 漏洞描述 Lotus Domino R5 and R6 WebMail with 'Generate HTML for all fields' enabled (which...
CVE-2023-27847: PrestaShop xipblog - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-27847: PrestaShop xipblog – SQL Injection

漏洞标题 CVE-2023-27847: PrestaShop xipblog - SQL Injection 漏洞描述 In the blog module (xipblog), an anonymous user can perform SQL injection. Even though the module has been patc...
xxe快速验证-渗透云记 - 专注于网络安全与技术分享

xxe快速验证

有回显,用以下poc直接读取/etc/passwd: <?xml version='1.0'?> <!DOCTYPE foo [ <!ELEMENT foo (#ANY)> <!ENTITY xxe SYSTEM 'file:///etc/passwd'>]><foo>&am...
2022年3月10日 23:37
010
CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader - Deserialization-渗透云记 - 专注于网络安全与技术分享

CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader – Deserialization

漏洞标题 CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader - Deserialization 漏洞描述 SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper a...
CVE-2019-2767: Oracle Business Intelligence Publisher - XML External Entity Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2019-2767: Oracle Business Intelligence Publisher – XML External Entity Injection

漏洞标题 CVE-2019-2767: Oracle Business Intelligence Publisher - XML External Entity Injection 漏洞描述 Oracle Business Intelligence Publisher is vulnerable to an XML external enti...
CVE-2021-24169: WordPress Advanced Order Export For WooCommerce <3.1.8 - Authenticated Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2021-24169: WordPress Advanced Order Export For WooCommerce <3.1.8 - Authenticated Cross-Site Scripting

漏洞标题 CVE-2021-24169: WordPress Advanced Order Export For WooCommerce <3.1.8 - Authenticated Cross-Site Scripting 漏洞描述 WordPress Advanced Order Export For WooCommerce plu...
CVE-2021-26599: ImpressCMS < 1.4.3 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-26599: ImpressCMS < 1.4.3 - SQL Injection

漏洞标题 CVE-2021-26599: ImpressCMS < 1.4.3 - SQL Injection 漏洞描述 ImpressCMS before 1.4.3 is vulnerable to SQL injection via the groups parameter in include/findusers.php, al...
CVE-2018-11222: Pandora FMS <=7.0NG.722 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2018-11222: Pandora FMS <=7.0NG.722 - Remote Code Execution

漏洞标题 CVE-2018-11222: Pandora FMS <=7.0NG.722 - Remote Code Execution 漏洞描述 Pandora FMS versions <=7.0NG.722 are vulnerable to unauthenticated remote code execution by ...
CVE-2023-0968: WordPress Watu Quiz <3.3.9.1 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-0968: WordPress Watu Quiz <3.3.9.1 - Cross-Site Scripting

漏洞标题 CVE-2023-0968: WordPress Watu Quiz <3.3.9.1 - Cross-Site Scripting 漏洞描述 WordPress Watu Quiz plugin before 3.3.9.1 is susceptible to cross-site scripting. The plugin...
CVE-2010-0942: Joomla! Component com_jvideodirect - Directory Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2010-0942: Joomla! Component com_jvideodirect – Directory Traversal

漏洞标题 CVE-2010-0942: Joomla! Component com_jvideodirect - Directory Traversal 漏洞描述 Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joo...
CVE-2021-24827: WordPress Asgaros Forum <1.15.13 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-24827: WordPress Asgaros Forum <1.15.13 - SQL Injection

漏洞标题 CVE-2021-24827: WordPress Asgaros Forum <1.15.13 - SQL Injection 漏洞描述 WordPress Asgaros Forum plugin before 1.15.13 is susceptible to SQL injection. The plugin does...
CVE-2022-1020: WordPress WooCommerce <3.1.2 - Arbitrary Function Call-渗透云记 - 专注于网络安全与技术分享

CVE-2022-1020: WordPress WooCommerce <3.1.2 - Arbitrary Function Call

漏洞标题 CVE-2022-1020: WordPress WooCommerce <3.1.2 - Arbitrary Function Call 漏洞描述 WordPress WooCommerce plugin before 3.1.2 does not have authorisation and CSRF checks in ...
CVE-2021-36888: WordPress Image Hover Ultimate - Unauthenticated Settings Update-渗透云记 - 专注于网络安全与技术分享

CVE-2021-36888: WordPress Image Hover Ultimate – Unauthenticated Settings Update

漏洞标题 CVE-2021-36888: WordPress Image Hover Ultimate - Unauthenticated Settings Update 漏洞描述 Unauthenticated Arbitrary Options Update vulnerability leading to full website co...
CVE-2021-24370: WordPress Fancy Product Designer <4.6.9 - Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2021-24370: WordPress Fancy Product Designer <4.6.9 - Arbitrary File Upload

漏洞标题 CVE-2021-24370: WordPress Fancy Product Designer <4.6.9 - Arbitrary File Upload 漏洞描述 WordPress Fancy Product Designer plugin before 4.6.9 is susceptible to an arbit...
CVE-2021-27670: Appspace 6.2.4 - Server-Side Request Forgery-渗透云记 - 专注于网络安全与技术分享

CVE-2021-27670: Appspace 6.2.4 – Server-Side Request Forgery

漏洞标题 CVE-2021-27670: Appspace 6.2.4 - Server-Side Request Forgery 漏洞描述 Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter. PoC代码