Show filters
63 Total Results
Displaying 51-60 of 63
Sort by:
Attacker Value
Unknown
CVE-2021-39501
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.
0
Attacker Value
Unknown
CVE-2021-39500
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, type, nid an attacker can inject "../" to escape and write file to writeable directories.
0
Attacker Value
Unknown
CVE-2021-39497
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.
0
Attacker Value
Unknown
CVE-2021-39499
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function.
0
Attacker Value
Unknown
CVE-2021-39496
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS.
0
Attacker Value
Unknown
CVE-2020-20642
Disclosure Date: August 19, 2021 (last updated February 23, 2025)
Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filemanager&a=newfile&lang=cn.
0
Attacker Value
Unknown
CVE-2020-20645
Disclosure Date: August 19, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.
0
Attacker Value
Unknown
CVE-2020-19669
Disclosure Date: August 18, 2021 (last updated February 23, 2025)
Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn.
0
Attacker Value
Unknown
CVE-2020-28146
Disclosure Date: August 18, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.
0
Attacker Value
Unknown
CVE-2020-21930
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.
0