Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IPFire.org | IPFire | 0 ~ 2.29 (Core Update 198) | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-34308 | IPFire < v2.29 Stored XSS via Default Time Sync | |
| CVE-2025-34313 | IPFire < v2.29 Stored XSS via User Quota Rule URL Filter | |
| CVE-2025-34311 | IPFire < v2.29 Command Injection via Proxy Report Creation | |
| CVE-2025-34318 | IPFire < v2.29 Stored XSS via DNS Creation (proxy.cgi) | |
| CVE-2025-34312 | IPFire < v2.29 Command Injection via URL Filter Blacklist | |
| CVE-2025-34316 | IPFire < v2.29 Stored XSS via Mail Server Settings | |
| CVE-2025-34317 | IPFire < v2.29 Stored XSS via DNS Creation (dns.cgi) | |
| CVE-2025-34310 | IPFire < v2.29 Stored XSS via Quality of Service (QoS) Settings | |
| CVE-2025-34307 | IPFire < v2.29 Stored XSS via Default Country Search | |
| CVE-2025-34305 | IPFire < v2.29 Stored XSS via Multiple Methods in cleanhtml() | |
| CVE-2025-34309 | IPFire < v2.29 Stored XSS via Dynamic DNS Host | |
| CVE-2025-34314 | IPFire < v2.29 Stored XSS via Time Constraint Rule URL Filter | |
| CVE-2025-34306 | IPFire < v2.29 Stored XSS via Default IP Search Value | |
| CVE-2025-34315 | IPFire < v2.29 Stored XSS via Remote Syslog Server Address | |
| CVE-2025-34303 | IPFire < v2.29 Stored XSS via Whitelisted Host Creation | |
| CVE-2025-34304 | IPFire < v2.29 SQL Injection via OpenVPN Connection Logs | |
| CVE-2025-34302 | IPFire < v2.29 Stored XSS via Service Creation |
No comments yet