Show filters
5,502 Total Results
Displaying 211-220 of 5,502
Sort by:
Attacker Value
Unknown
CVE-2024-42606
Disclosure Date: August 20, 2024 (last updated August 22, 2024)
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1
0
Attacker Value
Unknown
CVE-2024-42605
Disclosure Date: August 20, 2024 (last updated August 22, 2024)
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1
0
Attacker Value
Unknown
CVE-2024-42604
Disclosure Date: August 20, 2024 (last updated August 22, 2024)
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_group.php?mode=delete&group_id=3
0
Attacker Value
Unknown
CVE-2024-42603
Disclosure Date: August 20, 2024 (last updated August 22, 2024)
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall
0
Attacker Value
Unknown
CVE-2024-8005
Disclosure Date: August 20, 2024 (last updated August 22, 2024)
A vulnerability was found in demozx gf_cms 1.0/1.0.1. It has been classified as critical. This affects the function init of the file internal/logic/auth/auth.go of the component JWT Authentication. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.2 is able to address this issue. The patch is named be702ada7cb6fdabc02689d90b38139c827458a5. It is recommended to upgrade the affected component.
0
Attacker Value
Unknown
CVE-2024-42608
Disclosure Date: August 20, 2024 (last updated August 22, 2024)
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php.
0
Attacker Value
Unknown
CVE-2024-7927
Disclosure Date: August 19, 2024 (last updated September 05, 2024)
A vulnerability classified as critical was found in ZZCMS 2023. Affected by this vulnerability is an unknown functionality of the file /admin/class.php?dowhat=modifyclass. The manipulation of the argument skin[] leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-7926
Disclosure Date: August 19, 2024 (last updated September 05, 2024)
A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify. The manipulation of the argument skin leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-7925
Disclosure Date: August 19, 2024 (last updated August 21, 2024)
A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation of the argument phome with the input ShowPHPInfo leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-7924
Disclosure Date: August 19, 2024 (last updated August 21, 2024)
A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of the file /I/list.php. The manipulation of the argument skin leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
0