mirror of
https://github.com/nomi-sec/PoC-in-GitHub.git
synced 2026-01-27 21:59:05 +01:00
33 lines
No EOL
1.6 KiB
JSON
33 lines
No EOL
1.6 KiB
JSON
[
|
||
{
|
||
"id": 1134825870,
|
||
"name": "WordPress-News-and-Blog-Designer-Bundle-CVE-2025-14502",
|
||
"full_name": "Kai-One001\/WordPress-News-and-Blog-Designer-Bundle-CVE-2025-14502",
|
||
"owner": {
|
||
"login": "Kai-One001",
|
||
"id": 76192879,
|
||
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/76192879?v=4",
|
||
"html_url": "https:\/\/github.com\/Kai-One001",
|
||
"user_view_type": "public"
|
||
},
|
||
"html_url": "https:\/\/github.com\/Kai-One001\/WordPress-News-and-Blog-Designer-Bundle-CVE-2025-14502",
|
||
"description": "WordPress的News and Blog Designer Bundle插件在1.1及之前所有版本中,存在通过template参数导致的本地文件包含漏洞。该漏洞使得未经身份验证的攻击者能够包含并执行服务器上的任意.php文件,从而运行这些文件中的任何PHP代码。在允许上传和包含.php文件类型的场景下,攻击者可利用此漏洞绕过访问控制、获取敏感数据或实现代码执行。",
|
||
"fork": false,
|
||
"created_at": "2026-01-15T09:00:28Z",
|
||
"updated_at": "2026-01-15T23:23:26Z",
|
||
"pushed_at": "2026-01-15T09:15:56Z",
|
||
"stargazers_count": 1,
|
||
"watchers_count": 1,
|
||
"has_discussions": false,
|
||
"forks_count": 0,
|
||
"allow_forking": true,
|
||
"is_template": false,
|
||
"web_commit_signoff_required": false,
|
||
"topics": [],
|
||
"visibility": "public",
|
||
"forks": 0,
|
||
"watchers": 1,
|
||
"score": 0,
|
||
"subscribers_count": 0
|
||
}
|
||
] |