高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| ベンダー | プロダクト | 影響を受けるバージョン | CPE | 購読 |
|---|---|---|---|---|
| Unknown | CDI – Collect and Deliver Interface for Woocommerce | 5.1.9 ~ 5.1.9 | - |
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|---|---|---|
| 1 | WordPress CDI plugin prior to 5.1.9 contains a cross-site scripting vulnerability. The plugin does not sanitize and escape a parameter before outputting it back in the response of an AJAX action. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1933.yaml | POC詳細 |
公開POCは見つかりませんでした。
ログインしてAI POCを生成| CVE-2022-2146 | Import CSV Files <= 1.0 - Reflected Cross-Site Scripting | |
| CVE-2021-24655 | WP User Manager < 2.6.3 - Arbitrary User Password Reset to Account Compromise | |
| CVE-2022-1672 | Insights from Google PageSpeed < 4.0.7 - Multiple CSRF | |
| CVE-2022-2090 | Woo Discount Rules < 2.4.2 - Reflected Cross-Site Scripting | |
| CVE-2022-2099 | WooCommerce < 6.6.0 - Admin+ Stored HTML Injection | |
| CVE-2022-2100 | Page Generator Plugin < 1.6.5 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2114 | Data Tables Generator by Supsystic < 1.10.20 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2118 | 404s < 3.5.1 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2133 | OAuth Single Sign On < 6.22.6 - Authentication Bypass | |
| CVE-2022-2144 | Jquery Validation For Contact Form 7 < 5.3 - Arbitrary Options Update via CSRF | |
| CVE-2022-2222 | Download Monitor < 4.5.91 - Admin+ Arbitrary File Download | |
| CVE-2022-2148 | LinkedIn Company Updates <= 1.5.3 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2149 | Very Simple Breadcrumb <= 1.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2151 | Best Contact Management Software <= 3.7.3 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2168 | Download Manager < 3.2.44 - Reflected Cross-Site Scripting | |
| CVE-2022-2169 | Loading Page with Loading Screen < 1.0.83 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2173 | Advanced Database Cleaner < 3.1.1 - Reflected Cross-Site Scripting | |
| CVE-2022-2186 | Simple Post Notes < 1.7.6 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-2187 | Contact Form 7 Captcha < 0.1.2 - Reflected Cross-Site Scripting | |
| CVE-2022-2194 | Accept Stripe Payments < 2.0.64 - Admin+ Stored Cross-Site Scripting |
まだコメントはありません