Show filters
28 Total Results
Displaying 11-20 of 28
Sort by:
Attacker Value
Unknown
CVE-2020-19142
Disclosure Date: December 10, 2020 (last updated February 22, 2025)
iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.
0
Attacker Value
Unknown
CVE-2020-24739
Disclosure Date: September 10, 2020 (last updated February 22, 2025)
A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial administrator will be deleted.
0
Attacker Value
Unknown
CVE-2019-17583
Disclosure Date: October 14, 2019 (last updated November 27, 2024)
idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many comments, as demonstrated by the admincp.php?app=comment&perpage= substring followed by a large positive integer.
0
Attacker Value
Unknown
CVE-2019-17552
Disclosure Date: October 14, 2019 (last updated November 27, 2024)
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
0
Attacker Value
Unknown
CVE-2019-16677
Disclosure Date: September 21, 2019 (last updated November 27, 2024)
An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
0
Attacker Value
Unknown
CVE-2019-11427
Disclosure Date: April 22, 2019 (last updated November 27, 2024)
An XSS issue was discovered in app/search/search.app.php in idreamsoft iCMS 7.0.14 via the public/api.php?app=search q parameter.
0
Attacker Value
Unknown
CVE-2019-11426
Disclosure Date: April 22, 2019 (last updated November 27, 2024)
An XSS issue was discovered in app/admincp/template/admincp.header.php in idreamsoft iCMS 7.0.14 via the admincp.php?app=config tab parameter.
0
Attacker Value
Unknown
CVE-2019-8902
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.
0
Attacker Value
Unknown
CVE-2019-7236
Disclosure Date: January 30, 2019 (last updated November 27, 2024)
An issue was discovered in idreamsoft iCMS 7.0.13. editor/editor.admincp.php allows admincp.php?app=editor&do=fileManager dir=../ Directory Traversal.
0
Attacker Value
Unknown
CVE-2019-7235
Disclosure Date: January 30, 2019 (last updated November 27, 2024)
An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to designate an arbitrary directory because of an apps.admincp.php error. This directory can then be deleted via an admincp.php?app=apps&do=uninstall request.
0