Show filters
123 Total Results
Displaying 111-120 of 123
Sort by:
Attacker Value
Unknown
CVE-2018-9174
Disclosure Date: April 02, 2018 (last updated November 26, 2024)
sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker's control.
0
Attacker Value
Unknown
CVE-2018-9175
Disclosure Date: April 02, 2018 (last updated November 26, 2024)
DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within the database is accessible to uploads/dede/sys_cache_up.php.
0
Attacker Value
Unknown
CVE-2018-9134
Disclosure Date: March 30, 2018 (last updated November 26, 2024)
file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .php file under the web root to achieve PHP code execution. This uses the oldfilename and newfilename parameters.
0
Attacker Value
Unknown
CVE-2018-7700
Disclosure Date: March 27, 2018 (last updated November 26, 2024)
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.
0
Attacker Value
Unknown
CVE-2018-6910
Disclosure Date: February 13, 2018 (last updated November 26, 2024)
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
0
Attacker Value
Unknown
CVE-2018-6881
Disclosure Date: February 12, 2018 (last updated November 26, 2024)
EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
0
Attacker Value
Unknown
CVE-2017-17727
Disclosure Date: December 18, 2017 (last updated November 26, 2024)
DedeCMS through 5.6 allows arbitrary file upload and PHP code execution by embedding the PHP code in a .jpg file, which is used in the templet parameter to member/article_edit.php.
0
Attacker Value
Unknown
CVE-2017-17731
Disclosure Date: December 18, 2017 (last updated November 26, 2024)
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
0
Attacker Value
Unknown
CVE-2017-17730
Disclosure Date: December 18, 2017 (last updated November 26, 2024)
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.
0
Attacker Value
Unknown
CVE-2011-5200
Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.
0