Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | MajorDoMo contains a remote code execution caused by an include order bug and lack of exit after redirect in admin panel's PHP console, letting unauthenticated attackers execute arbitrary PHP code via crafted GET requests. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-27174.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-27180 | 9.8 CRITICAL | MajorDoMo Supply Chain Remote Code Execution via Update URL Poisoning |
| CVE-2026-27175 | 9.8 CRITICAL | MajorDoMo Command Injection in rc/index.php via Race Condition |
| CVE-2026-27179 | 8.2 HIGH | MajorDoMo Unauthenticated SQL Injection in Commands Module |
| CVE-2026-27181 | 7.5 HIGH | MajorDoMo Unauthenticated Module Uninstall via Market Endpoint |
| CVE-2026-27177 | 7.2 HIGH | MajorDoMo Stored Cross-Site Scripting via Property Set Endpoint |
| CVE-2026-27178 | 7.2 HIGH | MajorDoMo Stored Cross-Site Scripting via Method Parameters to Shoutbox |
| CVE-2026-27176 | 6.1 MEDIUM | MajorDoMo Reflected Cross-Site Scripting in command.php |
No comments yet