Show filters
53 Total Results
Displaying 31-40 of 53
Sort by:
Attacker Value
Unknown

CVE-2019-9109

Disclosure Date: February 25, 2019 (last updated November 27, 2024)
XSS exists in WUZHI CMS 4.1.0 via index.php?m=message&f=message&v=add&username=[XSS] to coreframe/app/message/message.php.
0
Attacker Value
Unknown

CVE-2019-9110

Disclosure Date: February 25, 2019 (last updated November 27, 2024)
XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/postinfo.php.
0
Attacker Value
Unknown

CVE-2018-20572

Disclosure Date: December 28, 2018 (last updated November 27, 2024)
WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.
0
Attacker Value
Unknown

CVE-2018-18938

Disclosure Date: November 05, 2018 (last updated November 27, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field.
0
Attacker Value
Unknown

CVE-2018-18711

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info.
0
Attacker Value
Unknown

CVE-2018-18712

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1.
0
Attacker Value
Unknown

CVE-2018-17832

Disclosure Date: October 01, 2018 (last updated November 27, 2024)
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
0
Attacker Value
Unknown

CVE-2018-14512

Disclosure Date: July 23, 2018 (last updated November 27, 2024)
An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload is triggered.
Attacker Value
Unknown

CVE-2018-14472

Disclosure Date: July 20, 2018 (last updated November 27, 2024)
An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly into execution without any filtering, leading to SQL injection.
0
Attacker Value
Unknown

CVE-2018-11722

Disclosure Date: June 05, 2018 (last updated November 26, 2024)
WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.
0