Show filters
76 Total Results
Displaying 61-70 of 76
Sort by:
Attacker Value
Unknown
CVE-2018-14512
Disclosure Date: July 23, 2018 (last updated November 27, 2024)
An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload is triggered.
0
Attacker Value
Unknown
CVE-2018-14472
Disclosure Date: July 20, 2018 (last updated November 27, 2024)
An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly into execution without any filtering, leading to SQL injection.
0
Attacker Value
Unknown
CVE-2018-11722
Disclosure Date: June 05, 2018 (last updated November 26, 2024)
WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.
0
Attacker Value
Unknown
CVE-2018-11549
Disclosure Date: May 29, 2018 (last updated November 26, 2024)
An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring.
0
Attacker Value
Unknown
CVE-2018-11528
Disclosure Date: May 29, 2018 (last updated November 26, 2024)
WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.
0
Attacker Value
Unknown
CVE-2018-11493
Disclosure Date: May 26, 2018 (last updated November 26, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add.
0
Attacker Value
Unknown
CVE-2018-10391
Disclosure Date: April 26, 2018 (last updated November 26, 2024)
An issue was discovered in WUZHI CMS 4.1.0. There is XSS via the email parameter to the index.php?m=member&v=register URI.
0
Attacker Value
Unknown
CVE-2018-10367
Disclosure Date: April 25, 2018 (last updated November 26, 2024)
An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content section.
0
Attacker Value
Unknown
CVE-2018-10368
Disclosure Date: April 25, 2018 (last updated November 26, 2024)
An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an announcement.
0
Attacker Value
Unknown
CVE-2018-10311
Disclosure Date: April 24, 2018 (last updated November 26, 2024)
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.
0