Show filters
142 Total Results
Displaying 51-60 of 142
Sort by:
Attacker Value
Unknown

CVE-2020-18432

Disclosure Date: June 30, 2023 (last updated February 25, 2025)
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
Attacker Value
Unknown

CVE-2023-2926

Disclosure Date: May 27, 2023 (last updated February 25, 2025)
A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file member.php of the component Picture Upload Handler. The manipulation of the argument oldpic leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-230081 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-31707

Disclosure Date: May 19, 2023 (last updated February 25, 2025)
SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
Attacker Value
Unknown

CVE-2023-30090

Disclosure Date: May 05, 2023 (last updated February 24, 2025)
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows attackers to execute arbitrary code via uploading a crafted PHP file.
Attacker Value
Unknown

CVE-2023-0960

Disclosure Date: February 22, 2023 (last updated February 24, 2025)
A vulnerability was found in SeaCMS 11.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/config.ftp.php of the component Picture Management. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-221630 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-48093

Disclosure Date: February 01, 2023 (last updated February 24, 2025)
Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.
Attacker Value
Unknown

CVE-2021-39426

Disclosure Date: December 15, 2022 (last updated February 24, 2025)
An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set.
Attacker Value
Unknown

CVE-2022-43256

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.
Attacker Value
Unknown

CVE-2021-38730

Disclosure Date: October 28, 2022 (last updated February 24, 2025)
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
Attacker Value
Unknown

CVE-2021-38733

Disclosure Date: October 28, 2022 (last updated February 24, 2025)
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.