Show filters
33 Total Results
Displaying 21-30 of 33
Sort by:
Attacker Value
Unknown

CVE-2018-14513

Disclosure Date: July 23, 2018 (last updated November 27, 2024)
An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[content] parameter to the index.php?m=feedback&f=index&v=contact URI.
0
Attacker Value
Unknown

CVE-2018-14515

Disclosure Date: July 23, 2018 (last updated November 27, 2024)
A SQL injection was discovered in WUZHI CMS 4.1.0 that allows remote attackers to inject a malicious SQL statement via the index.php?m=promote&f=index&v=search keywords parameter.
0
Attacker Value
Unknown

CVE-2018-14512

Disclosure Date: July 23, 2018 (last updated November 27, 2024)
An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload is triggered.
Attacker Value
Unknown

CVE-2018-11549

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring.
0
Attacker Value
Unknown

CVE-2018-11528

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.
0
Attacker Value
Unknown

CVE-2018-11493

Disclosure Date: May 26, 2018 (last updated November 26, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add.
0
Attacker Value
Unknown

CVE-2018-10391

Disclosure Date: April 26, 2018 (last updated November 26, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is XSS via the email parameter to the index.php?m=member&v=register URI.
0
Attacker Value
Unknown

CVE-2018-10367

Disclosure Date: April 25, 2018 (last updated November 26, 2024)
An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content section.
0
Attacker Value
Unknown

CVE-2018-10368

Disclosure Date: April 25, 2018 (last updated November 26, 2024)
An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an announcement.
0
Attacker Value
Unknown

CVE-2018-10311

Disclosure Date: April 24, 2018 (last updated November 26, 2024)
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.
0