Show filters
267 Total Results
Displaying 201-210 of 267
Sort by:
Attacker Value
Unknown
CVE-2018-18782
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.
0
Attacker Value
Unknown
CVE-2018-18608
Disclosure Date: October 23, 2018 (last updated November 27, 2024)
DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is used to display the page numbers list at the bottom of some templates, as demonstrated by the PATH_INFO to /member/index.php, /member/pm.php, /member/content_list.php, or /plus/feedback.php.
0
Attacker Value
Unknown
CVE-2018-18579
Disclosure Date: October 22, 2018 (last updated November 27, 2024)
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/pm.php folder parameter.
0
Attacker Value
Unknown
CVE-2018-18578
Disclosure Date: October 22, 2018 (last updated November 27, 2024)
DedeCMS 5.7 SP2 allows XSS via the plus/qrcode.php type parameter.
0
Attacker Value
Unknown
CVE-2018-16786
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php.
0
Attacker Value
Unknown
CVE-2018-16784
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring.
0
Attacker Value
Unknown
CVE-2018-16785
Disclosure Date: September 19, 2018 (last updated November 27, 2024)
XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell
0
Attacker Value
Unknown
CVE-2018-14402
Disclosure Date: July 19, 2018 (last updated November 27, 2024)
axmldec 1.2.0 has an out-of-bounds write in the jitana::axml_parser::parse_start_namespace function in lib/jitana/util/axml_parser.cpp.
0
Attacker Value
Unknown
CVE-2018-13587
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for DECToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown
CVE-2018-13732
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for RiptideCoin (RIPT), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0