Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-1982

EPSS 0.80% · P74
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-1982

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ss_id parameter.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
WordPress wpSS插件ss_id参数SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。wpSS是其中的一个电子表格插件。 wpSS插件的wpSS/ss_load.php文件中没有正确地过滤对ss_id参数的数便用在了SQL查询中: ss_load.php $id = $_GET['ss_id']; .... ss_functions.php: function ss_load ($id, $plain=FALSE) { .... if ($wpdb-
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-1982

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-1982

登录查看更多情报信息。

Same Patch Batch · n/a · 2008-04-27 · 29 CVEs total

CVE-2008-1980drupal e-publish 跨站脚本攻击漏洞
CVE-2008-1973SubEdit播放器字幕文件处理堆溢出漏洞
CVE-2008-1972Exponent CMS 跨站脚本攻击漏洞
CVE-2008-1971phShoutBox Final 安全绕过漏洞
CVE-2008-1970mucommander 信任管理漏洞
CVE-2008-1969Cezanne 多个跨站脚本攻击漏洞
CVE-2008-1968Cezanne 'FUNID' 参数 多个SQL 注入漏洞
CVE-2008-1967Cezanne Software 'CFLogon.asp'跨站脚本攻击漏洞
CVE-2008-1966IBM DB2数据库JAR文件处理多个拒绝服务漏洞
CVE-2008-1975E-RESERV index.php SQL注入漏洞
CVE-2008-1974Horde Webmail 'addevent.php'跨站脚本攻击漏洞
CVE-2008-1984CA eTrust Secure Content Manager eCSqdmn远程拒绝服务漏洞
CVE-2008-1983Advanced Electron Forum 'beg'参数 跨站脚本攻击漏洞
CVE-2008-1981drupa e-publish 跨站请求伪造漏洞
CVE-2008-1985Digital Hive 'base.php'参数跨站脚本攻击漏洞
CVE-2008-1979CA ARCserve Backup Discovery服务远程拒绝服务漏洞
CVE-2008-1978Drupal Ubercart 跨站脚本攻击漏洞
CVE-2008-1977Drupal多个跨站请求伪造漏洞
CVE-2008-1976Drupal 多个跨站脚本攻击和请求伪造漏洞
CVE-2008-1994Acon 多个缓冲区溢出漏洞

Showing top 20 of 29 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-1982

No comments yet


Leave a comment