Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2019-11617

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "Google Analytics code" modification.
0
Attacker Value
Unknown

CVE-2019-11607

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copydir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.
0
Attacker Value
Unknown

CVE-2019-11614

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/commentView.php. A remote unauthorized attacker could exploit the vulnerability to obtain database sensitive information.
0
Attacker Value
Unknown

CVE-2019-11620

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permission to manage modulecategory) could exploit the vulnerability to obtain database sensitive information via modulecategory_add_titre.
0
Attacker Value
Unknown

CVE-2019-11606

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.
0
Attacker Value
Unknown

CVE-2019-11625

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/emailingRequest.php. A remote background administrator privilege user (or a user with permission to manage emailing) could exploit the vulnerability to obtain database sensitive information.
0
Attacker Value
Unknown

CVE-2019-11626

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
routers/ajaxRouter.php in doorGets 7.0 has a web site physical path leakage vulnerability, as demonstrated by an ajax/index.php?uri=1234%5c request.
0
Attacker Value
Unknown

CVE-2019-11624

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has an arbitrary file deletion vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote background administrator privilege user can exploit this vulnerability to delete arbitrary files.
0
Attacker Value
Unknown

CVE-2019-11611

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/download.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.
0
Attacker Value
Unknown

CVE-2019-11612

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has an arbitrary file deletion vulnerability in /fileman/php/deletefile.php. A remote unauthenticated attacker can exploit this vulnerability to delete arbitrary files.
0