Show filters
114 Total Results
Displaying 111-114 of 114
Sort by:
Attacker Value
Unknown

CVE-2011-5200

Disclosure Date: September 23, 2012 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.
0
Attacker Value
Unknown

CVE-2010-1097

Disclosure Date: March 24, 2010 (last updated October 04, 2023)
include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated by a request to uploads/include/dialog/select_soft_post.php.
0
Attacker Value
Unknown

CVE-2009-3806

Disclosure Date: October 27, 2009 (last updated October 04, 2023)
SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter.
0
Attacker Value
Unknown

CVE-2009-2270

Disclosure Date: July 01, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbitrary code by uploading a file with a double extension in the filename, then accessing this file via unspecified vectors, as demonstrated by a .jpg.php filename.
0