Show filters
63 Total Results
Displaying 51-60 of 63
Sort by:
Attacker Value
Unknown

CVE-2021-39501

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.
Attacker Value
Unknown

CVE-2021-39500

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, type, nid an attacker can inject "../" to escape and write file to writeable directories.
Attacker Value
Unknown

CVE-2021-39497

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.
Attacker Value
Unknown

CVE-2021-39499

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function.
Attacker Value
Unknown

CVE-2021-39496

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS.
Attacker Value
Unknown

CVE-2020-20642

Disclosure Date: August 19, 2021 (last updated February 23, 2025)
Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filemanager&a=newfile&lang=cn.
Attacker Value
Unknown

CVE-2020-20645

Disclosure Date: August 19, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.
Attacker Value
Unknown

CVE-2020-19669

Disclosure Date: August 18, 2021 (last updated February 23, 2025)
Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn.
Attacker Value
Unknown

CVE-2020-28146

Disclosure Date: August 18, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.
Attacker Value
Unknown

CVE-2020-21930

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.