Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2019-11617
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "Google Analytics code" modification.
0
Attacker Value
Unknown
CVE-2019-11607
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copydir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.
0
Attacker Value
Unknown
CVE-2019-11614
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/commentView.php. A remote unauthorized attacker could exploit the vulnerability to obtain database sensitive information.
0
Attacker Value
Unknown
CVE-2019-11620
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permission to manage modulecategory) could exploit the vulnerability to obtain database sensitive information via modulecategory_add_titre.
0
Attacker Value
Unknown
CVE-2019-11606
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.
0
Attacker Value
Unknown
CVE-2019-11625
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/emailingRequest.php. A remote background administrator privilege user (or a user with permission to manage emailing) could exploit the vulnerability to obtain database sensitive information.
0
Attacker Value
Unknown
CVE-2019-11626
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
routers/ajaxRouter.php in doorGets 7.0 has a web site physical path leakage vulnerability, as demonstrated by an ajax/index.php?uri=1234%5c request.
0
Attacker Value
Unknown
CVE-2019-11624
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has an arbitrary file deletion vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote background administrator privilege user can exploit this vulnerability to delete arbitrary files.
0
Attacker Value
Unknown
CVE-2019-11611
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/download.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.
0
Attacker Value
Unknown
CVE-2019-11612
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has an arbitrary file deletion vulnerability in /fileman/php/deletefile.php. A remote unauthenticated attacker can exploit this vulnerability to delete arbitrary files.
0