Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | DNN (DotNetNuke) versions 9.2 through 9.2.2 use a weak encryption algorithm to protect input parameters because of an incomplete fix for CVE-2018-15811. This cryptographic weakness enables attackers to craft malicious DNNPersonalization cookies that can be deserialized, leading to remote code execution. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-18325.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2017-18346 | CMS Web-Gooroo SQL注入漏洞 | |
| CVE-2018-11425 | Moxa OnCell G3470A-LTE 缓冲区错误漏洞 | |
| CVE-2018-10986 | Open-Xchange Guard 跨站请求伪造漏洞 | |
| CVE-2017-9327 | Cloudera Manager 授权问题漏洞 | |
| CVE-2017-9326 | Cloudera Manager 信任管理问题漏洞 | |
| CVE-2017-9325 | Cloudera Manager 授权问题漏洞 | |
| CVE-2018-15811 | DNN 加密问题漏洞 | |
| CVE-2017-6900 | RIELLO UPS NetMan 信任管理问题漏洞 | |
| CVE-2017-6216 | novaksolutions/infusionsoft-php-sdk 跨站脚本漏洞 | |
| CVE-2018-11686 | Devaldi FlexPaper 输入验证错误漏洞 | |
| CVE-2019-13186 | MiniCMS 跨站脚本漏洞 | |
| CVE-2018-15812 | DNN 安全特征问题漏洞 | |
| CVE-2017-17972 | Archon 跨站脚本漏洞 | |
| CVE-2018-18326 | DNN 安全特征问题漏洞 | |
| CVE-2018-12250 | Elite Graphix Elite CMS Pro SQL注入漏洞 | |
| CVE-2018-12715 | DIGISOL SYSTEMS DG-HR3400 跨站脚本漏洞 | |
| CVE-2019-12570 | WordPress Server Status by Hostname/IP插件SQL注入漏洞 | |
| CVE-2019-7165 | DOSBox 缓冲区错误漏洞 | |
| CVE-2018-14866 | Odoo 权限许可和访问控制问题漏洞 | |
| CVE-2019-9823 | JetBrains IntelliJ IDEA 信任管理问题漏洞 |
Showing top 20 of 74 CVEs. View all on vendor page → →
No comments yet