Show filters
123 Total Results
Displaying 101-110 of 123
Sort by:
Attacker Value
Unknown

CVE-2018-18782

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.
0
Attacker Value
Unknown

CVE-2018-18608

Disclosure Date: October 23, 2018 (last updated November 27, 2024)
DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is used to display the page numbers list at the bottom of some templates, as demonstrated by the PATH_INFO to /member/index.php, /member/pm.php, /member/content_list.php, or /plus/feedback.php.
0
Attacker Value
Unknown

CVE-2018-18579

Disclosure Date: October 22, 2018 (last updated November 27, 2024)
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/pm.php folder parameter.
0
Attacker Value
Unknown

CVE-2018-18578

Disclosure Date: October 22, 2018 (last updated November 27, 2024)
DedeCMS 5.7 SP2 allows XSS via the plus/qrcode.php type parameter.
0
Attacker Value
Unknown

CVE-2018-16786

Disclosure Date: September 21, 2018 (last updated November 27, 2024)
DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php.
0
Attacker Value
Unknown

CVE-2018-16784

Disclosure Date: September 21, 2018 (last updated November 27, 2024)
DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring.
0
Attacker Value
Unknown

CVE-2018-16785

Disclosure Date: September 19, 2018 (last updated November 27, 2024)
XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell
0
Attacker Value
Unknown

CVE-2018-12046

Disclosure Date: June 08, 2018 (last updated November 26, 2024)
DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=newfile request with name and str parameters, as demonstrated by writing to a new .php file.
0
Attacker Value
Unknown

CVE-2018-12045

Disclosure Date: June 08, 2018 (last updated November 26, 2024)
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file.
0
Attacker Value
Unknown

CVE-2018-10375

Disclosure Date: April 25, 2018 (last updated November 26, 2024)
A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to upload and execute arbitrary PHP code via the /dede/archives_do.php?dopost=uploadLitpic litpic parameter when "Content-Type: image/jpeg" is sent, but the filename ends in .php and contains PHP code.
0