Show filters
114 Total Results
Displaying 31-40 of 114
Sort by:
Attacker Value
Unknown
CVE-2023-49492
Disclosure Date: December 07, 2023 (last updated December 13, 2023)
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php.
0
Attacker Value
Unknown
CVE-2023-43275
Disclosure Date: November 16, 2023 (last updated November 21, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form.
0
Attacker Value
Unknown
CVE-2023-48068
Disclosure Date: November 13, 2023 (last updated November 17, 2023)
DedeCMS v6.2 was discovered to contain a Cross-site Scripting (XSS) vulnerability via spec_add.php.
0
Attacker Value
Unknown
CVE-2023-5301
Disclosure Date: September 30, 2023 (last updated October 08, 2023)
A vulnerability classified as critical was found in DedeCMS 5.7.111. This vulnerability affects the function AddMyAddon of the file album_add.php. The manipulation of the argument albumUploadFiles leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240940.
0
Attacker Value
Unknown
CVE-2023-43226
Disclosure Date: September 28, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
0
Attacker Value
Unknown
CVE-2023-5022
Disclosure Date: September 17, 2023 (last updated October 08, 2023)
A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepath leads to absolute path traversal. The associated identifier of this vulnerability is VDB-239863.
0
Attacker Value
Unknown
CVE-2023-40784
Disclosure Date: September 12, 2023 (last updated October 08, 2023)
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.
0
Attacker Value
Unknown
CVE-2023-4747
Disclosure Date: September 04, 2023 (last updated October 08, 2023)
A vulnerability classified as critical was found in DedeCMS 5.7.110. This vulnerability affects unknown code of the file /uploads/tags.php. The manipulation of the argument tag_alias leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-238636.
0
Attacker Value
Unknown
CVE-2023-40877
Disclosure Date: August 24, 2023 (last updated October 08, 2023)
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title parameter.
0
Attacker Value
Unknown
CVE-2023-40876
Disclosure Date: August 24, 2023 (last updated October 08, 2023)
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter.
0