Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
CVE-2023-37847
Disclosure Date: August 14, 2023 (last updated October 08, 2023)
novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.
0
Attacker Value
Unknown
CVE-2021-30048
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Directory Traversal in the fileDownload function in com/java2nb/common/controller/FileController.java in Novel-plus (小说精品屋-plus) 3.5.1 allows attackers to read arbitrary files via the filePath parameter.
0