Show filters
80 Total Results
Displaying 21-30 of 80
Sort by:
Attacker Value
Unknown
CVE-2019-17552
Disclosure Date: October 14, 2019 (last updated November 27, 2024)
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
0
Attacker Value
Unknown
CVE-2019-16677
Disclosure Date: September 21, 2019 (last updated November 27, 2024)
An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
0
Attacker Value
Unknown
CVE-2019-14976
Disclosure Date: August 12, 2019 (last updated November 27, 2024)
iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter.
0
Attacker Value
Unknown
CVE-2019-11616
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a sensitive information disclosure vulnerability in /setup/temp/admin.php and /setup/temp/database.php. A remote unauthenticated attacker could exploit this vulnerability to obtain the administrator password.
0
Attacker Value
Unknown
CVE-2019-11618
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this vulnerability to gain administrator privileges for the creation and modification of articles via an H0XZlT44FcN1j9LTdFc5XRXhlF30UaGe1g3cZY6i1K9 access_token in a uri=blog&action=index&controller=blog action to /api/index.php.
0
Attacker Value
Unknown
CVE-2019-11621
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=network. A remote background administrator privilege user (or a user with permission to manage network configuration) could exploit the vulnerability to obtain database sensitive information.
0
Attacker Value
Unknown
CVE-2019-11615
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
/fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can use this vulnerability to upload backdoor files to control the server.
0
Attacker Value
Unknown
CVE-2019-11609
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/movefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information or make the server unserviceable.
0
Attacker Value
Unknown
CVE-2019-11622
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permission to manage modulecategory) could exploit the vulnerability to obtain database sensitive information via modulecategory_edit_titre.
0
Attacker Value
Unknown
CVE-2019-11613
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/contactView.php. A remote normal registered user could exploit the vulnerability to obtain database sensitive information.
0