高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| ベンダー | プロダクト | 影響を受けるバージョン | CPE | 購読 |
|---|---|---|---|---|
| Unknown | Pricing Table Plugin | 3.6.1 ~ 3.6.1 | - |
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|---|---|---|
| 1 | WordPress ARPrice plugin prior to 3.6.1 contains a SQL injection vulnerability. It fails to properly sanitize and escape user supplied POST data before being inserted in an SQL statement and executed via an AJAX action. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0867.yaml | POC詳細 |
公開POCは見つかりませんでした。
ログインしてAI POCを生成| CVE-2022-1393 | WP Subtitle < 3.4.1 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2022-1560 | Amministrazione Aperta < 3.8 - Admin+ LFI | |
| CVE-2022-1559 | Clipr <= 1.2.3 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1557 | ULeak Security & Monitoring <= 1.2.3 - Subscriber+ Stored Cross-Site Scripting | |
| CVE-2022-1512 | ScrollReveal.js Effects <= 1.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1465 | WPC Smart Wishlist for WooCommerce < 2.9.9 - Reflected Cross-Site Scripting | |
| CVE-2022-1455 | Call Now Button < 1.1.2 - Reflected Cross-Site Scripting | |
| CVE-2022-1436 | WPCargo Track & Trace < 6.9.5 - Reflected Cross Site Scripting | |
| CVE-2022-1435 | WPCargo Track & Trace < 6.9.5 - Admin+ Stored Cross Site Scripting | |
| CVE-2022-1425 | WPQA < 5.2 - Subscriber+ Private Message Disclosure via IDOR | |
| CVE-2022-1418 | Social Stickers <= 2.2.9 - Stored Cross-Site Scripting via CSRF | |
| CVE-2022-1409 | VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ PHP File Upload | |
| CVE-2022-1408 | VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1407 | VikBooking Hotel Booking Engine & PMS < 1.5.7 - Stored Cross-Site Scripting via CSRF | |
| CVE-2022-1398 | External Media without Import <= 1.1.2 - Subscriber+ Blind SSRF | |
| CVE-2021-25119 | AGIL <= 1.0 - Admin+ Arbitrary File Upload | |
| CVE-2022-1386 | Fusion Builder < 3.6.2 - Unauthenticated SSRF | |
| CVE-2022-1349 | WPQA < 5.2 - Subscriber+ Arbitrary Profile Picture Deletion via IDOR | |
| CVE-2022-1334 | WP YouTube Live < 1.8.3 - Admin+ Stored Cross Site Scripting | |
| CVE-2022-1267 | BMI BMR Calculator <= 1.3 - Reflected Cross-Site Scripting |
Showing 20 of 30 CVEs. View all on vendor page →
まだコメントはありません