Show filters
267 Total Results
Displaying 211-220 of 267
Sort by:
Attacker Value
Unknown
CVE-2018-13229
Disclosure Date: July 05, 2018 (last updated November 27, 2024)
The sell function of a smart contract implementation for RiptideCoin (RIPT), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.
0
Attacker Value
Unknown
CVE-2018-12046
Disclosure Date: June 08, 2018 (last updated November 26, 2024)
DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=newfile request with name and str parameters, as demonstrated by writing to a new .php file.
0
Attacker Value
Unknown
CVE-2018-12045
Disclosure Date: June 08, 2018 (last updated November 26, 2024)
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file.
0
Attacker Value
Unknown
CVE-2017-16070
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
0
Attacker Value
Unknown
CVE-2018-10813
Disclosure Date: June 05, 2018 (last updated November 26, 2024)
In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of Passport.js, this could lead to privilege escalation.
0
Attacker Value
Unknown
CVE-2017-16023
Disclosure Date: June 04, 2018 (last updated November 26, 2024)
Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to evaluate a string and takes unescaped separator values, which can be used to create a denial of service attack.
0
Attacker Value
Unknown
CVE-2018-10375
Disclosure Date: April 25, 2018 (last updated November 26, 2024)
A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to upload and execute arbitrary PHP code via the /dede/archives_do.php?dopost=uploadLitpic litpic parameter when "Content-Type: image/jpeg" is sent, but the filename ends in .php and contains PHP code.
0
Attacker Value
Unknown
CVE-2018-9174
Disclosure Date: April 02, 2018 (last updated November 26, 2024)
sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker's control.
0
Attacker Value
Unknown
CVE-2018-9175
Disclosure Date: April 02, 2018 (last updated November 26, 2024)
DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within the database is accessible to uploads/dede/sys_cache_up.php.
0
Attacker Value
Unknown
CVE-2018-9134
Disclosure Date: March 30, 2018 (last updated November 26, 2024)
file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .php file under the web root to achieve PHP code execution. This uses the oldfilename and newfilename parameters.
0