Xxyopen

Novel-plus

42 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 26.01.2024 19:15:08
  • Zuletzt bearbeitet 21.11.2024 08:47:49

A vulnerability was found in Novel-Plus 4.3.0-RC1 and classified as critical. This issue affects some unknown processing of the file /novel/bookComment/list. The manipulation of the argument sort leads to sql injection. The exploit has been disclosed...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 18.01.2024 03:15:59
  • Zuletzt bearbeitet 21.11.2024 08:47:05

A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The manipulation of the argument sort leads to sql injection. The explo...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 29.12.2023 18:15:39
  • Zuletzt bearbeitet 21.11.2024 08:45:25

A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java of the c...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 29.12.2023 09:15:09
  • Zuletzt bearbeitet 21.11.2024 08:45:25

A vulnerability classified as problematic has been found in Novel-Plus up to 4.2.0. This affects an unknown part of the file /user/updateUserInfo of the component HTTP POST Request Handler. The manipulation of the argument nickName leads to cross sit...

Exploit
  • EPSS 1.02%
  • Veröffentlicht 05.11.2023 00:15:08
  • Zuletzt bearbeitet 21.11.2024 08:29:35

SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list.

Exploit
  • EPSS 0.89%
  • Veröffentlicht 18.09.2023 22:15:47
  • Zuletzt bearbeitet 21.11.2024 08:21:12

SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 11.09.2023 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:59:45

novel-plus 3.6.2 is vulnerable to SQL Injection.

  • EPSS 0.3%
  • Veröffentlicht 14.08.2023 12:15:09
  • Zuletzt bearbeitet 01.08.2025 02:09:57

novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 14.04.2023 09:15:07
  • Zuletzt bearbeitet 21.11.2024 07:57:49

A vulnerability classified as critical was found in novel-plus 3.6.2. Affected by this vulnerability is an unknown functionality of the file /category/list?limit=10&offset=0&order=desc. The manipulation of the argument sort leads to sql injection. Th...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 14.04.2023 09:15:07
  • Zuletzt bearbeitet 21.11.2024 07:57:48

A vulnerability classified as critical has been found in novel-plus 3.6.2. Affected is an unknown function of the file /news/list?limit=10&offset=0&order=desc. The manipulation of the argument sort leads to sql injection. It is possible to launch the...