漏洞描述 Simple Image Stack Website是一个简单图片展示网站。 Simple Image Stack Website 1.0版本存在跨站脚本漏洞,该漏洞源于对参数page的错误操作会导致跨站点脚本编写。
相关漏洞推荐 POC CVE-2019-14206: Nevma Adaptive Images - Arbitrary File Deletion POC wp-really-simple-captcha-fpd: WordPress Plugin Really Simple CAPTCHA - Full Path Disclosure POC wp-simple-custom-css-fpd: WordPress Simple Custom CSS Plugin - Full Path Disclosure POC wordpress-menu-image-fpd: WordPress Menu Image - Full Path Disclosure POC CVE-2020-12832: WordPress Simple File List - Path Traversal POC CVE-2025-14611: Gladinet CentreStack & Triofox - Hardcoded Credentials POC imageresizer-debug-exposure: ImageResizer Debug - Information Exposure POC wp-image-widget-fpd: Image Widget - Full Path Disclosure POC wp-simple-301-redirects-fpd: Simple 301 Redirects - Full Path Disclosure POC wp-simple-custom-css-fpd: WordPress Simple Custom CSS Plugin - Full Path Disclosure (CVE-2025-15011)Simple Stock System 1.0 logout.php SQL注入漏洞 POC JNPF快速开发平台 /api/file/Image/userAvatar/aa 文件读取漏洞 Carmelo Simple_stock_system注入漏洞(CVE-2025-14834)