Show filters
233 Total Results
Displaying 41-50 of 233
Sort by:
Attacker Value
Unknown

CVE-2023-1680

Disclosure Date: March 29, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, has been found in Xunrui CMS 4.61. This issue affects some unknown processing of the file /dayrui/My/View/main.html. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224237 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-1683

Disclosure Date: March 29, 2023 (last updated February 24, 2025)
A vulnerability was found in Xunrui CMS 4.61 and classified as problematic. Affected by this issue is some unknown functionality of the file /dayrui/Fcms/View/system_log.html. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224240.
Attacker Value
Unknown

CVE-2023-1682

Disclosure Date: March 29, 2023 (last updated February 24, 2025)
A vulnerability has been found in Xunrui CMS 4.61 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dayrui/My/Config/Install.txt. The manipulation leads to direct request. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224239.
Attacker Value
Unknown

CVE-2023-1681

Disclosure Date: March 28, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in Xunrui CMS 4.61. Affected is an unknown function of the file /config/myfield/test.php. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-224238 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-30037

Disclosure Date: March 23, 2023 (last updated February 24, 2025)
XunRuiCMS v4.3.3 to v4.5.1 vulnerable to PHP file write and CMS PHP file inclusion, allows attackers to execute arbitrary php code, via the add function in cron.php.
Attacker Value
Unknown

CVE-2023-1565

Disclosure Date: March 22, 2023 (last updated February 24, 2025)
A vulnerability was found in FeiFeiCMS 2.7.130201. It has been classified as problematic. This affects an unknown part of the file \Public\system\slide_add.html of the component Extension Tool. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223557 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-27235

Disclosure Date: March 15, 2023 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to execute arbitrary code via a crafted phtml file.
Attacker Value
Unknown

CVE-2023-27234

Disclosure Date: March 15, 2023 (last updated February 24, 2025)
A Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configuration changes within the application.
Attacker Value
Unknown

CVE-2021-33387

Disclosure Date: February 24, 2023 (last updated February 24, 2025)
Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.
Attacker Value
Unknown

CVE-2021-36484

Disclosure Date: February 03, 2023 (last updated February 24, 2025)
SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page.