Show filters
53 Total Results
Displaying 31-40 of 53
Sort by:
Attacker Value
Unknown
CVE-2019-9109
Disclosure Date: February 25, 2019 (last updated November 27, 2024)
XSS exists in WUZHI CMS 4.1.0 via index.php?m=message&f=message&v=add&username=[XSS] to coreframe/app/message/message.php.
0
Attacker Value
Unknown
CVE-2019-9110
Disclosure Date: February 25, 2019 (last updated November 27, 2024)
XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/postinfo.php.
0
Attacker Value
Unknown
CVE-2018-20572
Disclosure Date: December 28, 2018 (last updated November 27, 2024)
WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.
0
Attacker Value
Unknown
CVE-2018-18938
Disclosure Date: November 05, 2018 (last updated November 27, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field.
0
Attacker Value
Unknown
CVE-2018-18711
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info.
0
Attacker Value
Unknown
CVE-2018-18712
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1.
0
Attacker Value
Unknown
CVE-2018-17832
Disclosure Date: October 01, 2018 (last updated November 27, 2024)
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
0
Attacker Value
Unknown
CVE-2018-14512
Disclosure Date: July 23, 2018 (last updated November 27, 2024)
An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload is triggered.
0
Attacker Value
Unknown
CVE-2018-14472
Disclosure Date: July 20, 2018 (last updated November 27, 2024)
An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly into execution without any filtering, leading to SQL injection.
0
Attacker Value
Unknown
CVE-2018-11722
Disclosure Date: June 05, 2018 (last updated November 26, 2024)
WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.
0