Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2024-7917

Disclosure Date: August 18, 2024 (last updated August 22, 2024)
A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue is some unknown functionality of the file /admin/system.php of the component Favicon Handler. The manipulation of the argument site_favicon leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2022-46438

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in the /admin/article_category.php component of DouPHP v1.7 20221118 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the description parameter.
Attacker Value
Unknown

CVE-2022-24131

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which will lead to JavaScript code execution.
Attacker Value
Unknown

CVE-2022-25574

Disclosure Date: March 25, 2022 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file.
Attacker Value
Unknown

CVE-2021-3370

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php.
Attacker Value
Unknown

CVE-2019-12564

Disclosure Date: June 03, 2019 (last updated November 27, 2024)
In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/DyyyymmddThhmmss.sql filenames.
0
Attacker Value
Unknown

CVE-2018-20560

Disclosure Date: December 28, 2018 (last updated November 27, 2024)
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/show.php?rec=update has XSS via the show_name parameter.
0
Attacker Value
Unknown

CVE-2018-20567

Disclosure Date: December 28, 2018 (last updated November 27, 2024)
An issue was discovered in DouCo DouPHP 1.5 20181221. \install\index.php allows a reload of the product in opportunistic circumstances in which install.lock cannot be read.
0
Attacker Value
Unknown

CVE-2018-20563

Disclosure Date: December 28, 2018 (last updated November 27, 2024)
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/mobile.php?rec=system&act=update has XSS via the mobile_name parameter.
0
Attacker Value
Unknown

CVE-2018-20557

Disclosure Date: December 28, 2018 (last updated November 27, 2024)
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/page.php?rec=edit has XSS via the page_name parameter.
0