Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2015-5528

EPSS 0.50% · P66
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2015-5528

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the save_order function in class-floating-social-bar.php in the Floating Social Bar plugin before 1.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the items[] parameter in an fsb_save_order action to wp-admin/admin-ajax.php.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
WordPress Floating Social Bar插件跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。Floating Social Bar是其中的一个社交媒体插件。 WordPress Floating Social Bar插件1.1.6之前版本的class-floating-social-bar.php脚本中的‘save_order’函数存在跨站脚本漏洞,该漏洞源于wp-admin/admin-ajax.php脚本没有充分过滤fsb_save_order操作中的
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2015-5528

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2015-5528

登录查看更多情报信息。

Vendor Advisories for CVE-2015-5528 (1)

Exploits & Public PoCs for CVE-2015-5528 (1)

Other References for CVE-2015-5528 (3)

Same Patch Batch · n/a · 2015-07-16 · 172 CVEs total

CVE-2015-4735Oracle Enterprise Manager Grid Control Enterprise Manager for Oracle Database组件安全漏洞
CVE-2015-2662Oracle Sun Systems Products Suite Solaris组件拒绝服务漏洞
CVE-2015-2663Oracle Supply Chain Products Suite Transportation Management组件安全漏洞
CVE-2015-2664Oracle Java SE Deployment子组件任意代码执行漏洞
CVE-2015-3244Red Hat JBoss Portal Portlet Bridge for JavaServer Faces 安全漏洞
CVE-2015-4727Oracle Virtualization Sun Ray Software组件安全漏洞
CVE-2015-4728Oracle E-Business Suite Sourcing组件安全漏洞
CVE-2015-4729Oracle Java SE Deployment子组件安全漏洞
CVE-2015-4731Oracle Java SE和Java SE Embedded JMX子组件任意代码执行漏洞
CVE-2015-4732Oracle Java SE和Java SE Embedded Libraries子组件任意代码执行漏洞
CVE-2015-4733Oracle Java SE和Java SE Embedded RMI子组件安全漏洞
CVE-2015-4740Oracle Database Server 任意命令执行漏洞
CVE-2015-4745Oracle Endeca Information Discovery Studio 安全漏洞
CVE-2015-4744Oracle GlassFish Server和Oracle WebLogic Server 安全漏洞
CVE-2015-4743Oracle E-Business Suite 安全漏洞
CVE-2015-4742Oracle JDeveloper 拒绝服务漏洞
CVE-2015-4741Oracle E-Business Suite Oracle Applications Framework组件安全漏洞
CVE-2015-4738Oracle PeopleSoft Products PeopleSoft Enterprise HCM Candidate Gateway组件安全漏洞
CVE-2015-4736Oracle Java SE Deployment子组件安全漏洞
CVE-2015-4737Oracle MySQL Server 安全漏洞

Showing top 20 of 172 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2015-5528

No comments yet


Leave a comment