Show filters
33 Total Results
Displaying 11-20 of 33
Sort by:
Attacker Value
Unknown

CVE-2019-9110

Disclosure Date: February 25, 2019 (last updated November 27, 2024)
XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/postinfo.php.
0
Attacker Value
Unknown

CVE-2018-18938

Disclosure Date: November 05, 2018 (last updated November 27, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field.
0
Attacker Value
Unknown

CVE-2018-18939

Disclosure Date: November 05, 2018 (last updated November 27, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via a seventh input field.
0
Attacker Value
Unknown

CVE-2018-18711

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info.
0
Attacker Value
Unknown

CVE-2018-18712

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1.
0
Attacker Value
Unknown

CVE-2018-17852

Disclosure Date: October 01, 2018 (last updated November 27, 2024)
A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the /index.php?m=coupon&f=card&v=detail_listing URI.
0
Attacker Value
Unknown

CVE-2018-16349

Disclosure Date: September 02, 2018 (last updated November 27, 2024)
WUZHI CMS 4.1.0 has XSS via the index.php?m=link&f=index&v=add form[remark] parameter.
0
Attacker Value
Unknown

CVE-2018-16350

Disclosure Date: September 02, 2018 (last updated November 27, 2024)
WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter.
0
Attacker Value
Unknown

CVE-2018-15893

Disclosure Date: August 27, 2018 (last updated November 27, 2024)
A SQL injection was discovered in /coreframe/app/admin/copyfrom.php in WUZHI CMS 4.1.0 via the index.php?m=core&f=copyfrom&v=listing keywords parameter.
0
Attacker Value
Unknown

CVE-2018-15894

Disclosure Date: August 27, 2018 (last updated November 27, 2024)
A SQL injection was discovered in /coreframe/app/admin/pay/admin/index.php in WUZHI CMS 4.1.0 via the index.php?m=pay&f=index&v=listing keyValue parameter.
0