Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC
| CVE-2017-0361 | api.log contains passwords in plaintext | |
| CVE-2017-0362 | "Mark all pages visited" on the watchlist does not require a CSRF token | |
| CVE-2017-0363 | Special:UserLogin?returnto=interwiki:foo will redirect to external sites | |
| CVE-2017-0365 | XSS in SearchHighlighter::highlightText() [requires non-default config] | |
| CVE-2017-0366 | SVG filter evasion using default attribute values in DTD declaration | |
| CVE-2017-0367 | Having LocalisationCache directory default to system tmp directory is insecure | |
| CVE-2017-0368 | Make rawHTML mode not apply to system messages | |
| CVE-2017-0369 | Sysops can undelete pages, although the page is protected against it | |
| CVE-2017-0370 | Spam blacklist ineffective on encoded URLs inside file inclusion syntax's link parameter | |
| CVE-2017-0372 | Parameters injection in SyntaxHighlight results in multiple vulnerabilities |
No comments yet