高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| ベンダー | プロダクト | 影響を受けるバージョン | CPE | 購読 |
|---|---|---|---|---|
| Adobe | Magento Commerce | unspecified ~ 2.4.5-p1 | - |
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|
公開POCは見つかりませんでした。
ログインしてAI POCを生成| CVE-2023-29297 | 9.1 CRITICAL | Admin-to-admin stored XSS via cache poisoning |
| CVE-2023-29321 | 7.8 HIGH | Adobe Animate FLA files Use After Free Arbitrary code execution |
| CVE-2023-21618 | 7.8 HIGH | ZDI-CAN-20963: Adobe Substance 3D Designer SBS File Parsing Uninitialized Variable Remote |
| CVE-2023-22248 | 7.5 HIGH | Adobe Commerce Incorrect Authorization Security feature bypass |
| CVE-2023-29289 | 6.5 MEDIUM | Adobe Commerce XML Injection Security feature bypass |
| CVE-2023-29304 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2023-29302 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2023-29307 | 5.4 MEDIUM | Open Redirect on AEM Target |
| CVE-2023-29322 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2023-29290 | 5.3 MEDIUM | Adobe Commerce Guest Cart Shipping Address Overwrite IDOR |
| CVE-2023-29287 | 5.3 MEDIUM | Adobe Commerce Information Exposure Security feature bypass |
| CVE-2023-29292 | 4.9 MEDIUM | Server Side Request Forgery (SSRF) in FedEx carrier integration configuration |
| CVE-2023-29291 | 4.9 MEDIUM | Server Side Request Forgery (SSRF) in USPS carrier integration configuration |
| CVE-2023-29295 | 4.3 MEDIUM | Insecure Direct Object Reference (IDOR) in Create Quote Function |
| CVE-2023-29294 | 4.3 MEDIUM | Bypass Purchase Order Approval using Company User in Adobe Commerce B2B |
| CVE-2023-29288 | 4.3 MEDIUM | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2023-29293 | 2.7 LOW | Adobe Commerce | Improper Input Validation (CWE-20) |
まだコメントはありません