高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| ベンダー | プロダクト | 影響を受けるバージョン | CPE | 購読 |
|---|---|---|---|---|
| Unknown | Limit Login Attempts (Spam Protection) | 5.1 ~ 5.1 | - |
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|---|---|---|
| 1 | The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0787.yaml | POC詳細 |
公開POCは見つかりませんでした。
ログインしてAI POCを生成| CVE-2022-0599 | Mapping Multiple URLs Redirect Same Page <= 5.8 - Reflected Cross-Site Scripting | |
| CVE-2022-0846 | SpeakOut! Email Petitions < 2.14.15.1 - Unauthenticated SQLi | |
| CVE-2022-0833 | Church Admin < 3.4.135 - Unauthenticated Plugin's Backup Disclosure | |
| CVE-2022-0818 | Coupon Affiliates < 4.16.4.5 - Unauthenticated Stored XSS | |
| CVE-2022-0784 | Title Experiments Free < 9.0.1 - Unauthenticated SQLi | |
| CVE-2022-0770 | Translate WordPress with GTranslate < 2.9.9 - CSRF to Account Takeover | |
| CVE-2022-0720 | Amelia < 1.0.47 - Customer+ Arbitrary Appointments Update and Sensitive Data Disclosure | |
| CVE-2022-0680 | Plezi < 1.0.3 - Unauthenticated Stored XSS | |
| CVE-2022-0679 | Narnoo Distributor <= 2.5.1 - Unauthenticated LFI to Arbitrary File Read / RCE | |
| CVE-2022-0647 | Bulk Creator <= 1.0.1 - Reflected Cross-Site Scripting | |
| CVE-2022-0643 | Bank Mellat <= 1.3.7 - Reflected Cross-Site Scripting | |
| CVE-2022-0641 | Popup Like box < 3.6.1 - Reflected Cross-Site Scripting | |
| CVE-2022-0621 | dTabs <= 1.4 - Reflected Cross-Site Scripting | |
| CVE-2022-0620 | Delete Old Orders <= 0.2 - Reflected Cross-Site Scripting | |
| CVE-2022-0619 | Database Peek <= 1.2 - Reflected Cross-Site Scripting | |
| CVE-2022-0600 | Conference Scheduler < 2.4.3 - Reflected Cross-Site Scripting | |
| CVE-2021-24746 | Sassy Social Share < 3.3.40 - Reflected Cross-Site Scripting | |
| CVE-2022-0595 | Drag and Drop Multiple File Upload - Contact Form 7 < 1.3.6.3 - Unauthenticated Stored XSS | |
| CVE-2022-0499 | Sermon Browser <= 0.45.22 - Arbitrary File Upload via CSRF | |
| CVE-2022-0493 | String Locator < 2.5.0 - Admin+ Arbitrary File Read |
Showing 20 of 32 CVEs. View all on vendor page →
まだコメントはありません