Show filters
233 Total Results
Displaying 11-20 of 233
Sort by:
Attacker Value
Unknown

CVE-2024-2016

Disclosure Date: March 21, 2024 (last updated March 21, 2024)
A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the argument sitename leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-255270 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown

CVE-2024-2015

Disclosure Date: March 21, 2024 (last updated March 21, 2024)
A vulnerability, which was classified as critical, has been found in ZhiCms 4.0. This issue affects the function getindexdata of the file app/index/controller/mcontroller.php. The manipulation of the argument key leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-255269 was assigned to this vulnerability.
0
Attacker Value
Unknown

CVE-2024-24388

Disclosure Date: February 02, 2024 (last updated February 09, 2024)
Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote attackers to obtain sensitive information via crafted malicious requests to the background login.
Attacker Value
Unknown

CVE-2024-0603

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250839.
Attacker Value
Unknown

CVE-2023-51154

Disclosure Date: January 04, 2024 (last updated January 11, 2024)
Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.
Attacker Value
Unknown

CVE-2023-50692

Disclosure Date: December 28, 2023 (last updated January 05, 2024)
File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.
Attacker Value
Unknown

CVE-2023-50011

Disclosure Date: December 14, 2023 (last updated December 20, 2023)
PopojiCMS version 2.0.1 is vulnerable to remote command execution in the Meta Social field.
Attacker Value
Unknown

CVE-2023-49490

Disclosure Date: December 11, 2023 (last updated December 14, 2023)
XunRuiCMS v4.5.5 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin.php.
Attacker Value
Unknown

CVE-2023-5910

Disclosure Date: November 02, 2023 (last updated November 09, 2023)
A vulnerability was found in PopojiCMS 2.0.1 and classified as problematic. This issue affects some unknown processing of the file install.php of the component Web Config. The manipulation of the argument Site Title with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-244229 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-46482

Disclosure Date: November 01, 2023 (last updated November 09, 2023)
SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.