Show filters
117 Total Results
Displaying 81-90 of 117
Sort by:
Attacker Value
Unknown

CVE-2019-8411

Disclosure Date: February 17, 2019 (last updated November 27, 2024)
admin/dl_data.php in zzcms 2018 (2018-10-19) allows remote attackers to delete arbitrary files via action=del&filename=../ directory traversal.
0
Attacker Value
Unknown

CVE-2019-7585

Disclosure Date: February 07, 2019 (last updated November 27, 2024)
An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/PublicAction.class.php allows time-based SQL Injection via the param array parameter to the /index.php?m=public&a=checkemail URI.
0
Attacker Value
Unknown

CVE-2019-7567

Disclosure Date: February 07, 2019 (last updated November 27, 2024)
An issue was discovered in Waimai Super Cms 20150505. admin.php?m=Member&a=adminaddsave has XSS via the username or password parameter.
0
Attacker Value
Unknown

CVE-2019-6127

Disclosure Date: January 11, 2019 (last updated November 27, 2024)
An issue was discovered in XiaoCms 20141229. It allows admin/index.php?c=database table[] SQL injection. This can be used for PHP code execution via "INTO OUTFILE" with a .php filename.
0
Attacker Value
Unknown

CVE-2019-3577

Disclosure Date: January 02, 2019 (last updated November 27, 2024)
An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/ProductAction.class.php allows blind SQL Injection via the id[0] parameter to the /product URI.
0
Attacker Value
Unknown

CVE-2018-19195

Disclosure Date: November 12, 2018 (last updated November 27, 2024)
An issue was discovered in XiaoCms 20141229. There is XSS related to the template\default\show_product.html file.
0
Attacker Value
Unknown

CVE-2018-19192

Disclosure Date: November 12, 2018 (last updated November 27, 2024)
An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content] parameter.
0
Attacker Value
Unknown

CVE-2018-19197

Disclosure Date: November 12, 2018 (last updated November 27, 2024)
An issue was discovered in XiaoCms 20141229. admin\controller\database.php allows arbitrary directory deletion via admin/index.php?c=database&a=import&paths[]=../ directory traversal.
0
Attacker Value
Unknown

CVE-2018-19194

Disclosure Date: November 12, 2018 (last updated November 27, 2024)
An issue was discovered in XiaoCms 20141229. /admin/index.php?c=database allows full path disclosure in a "failed to open stream" error message.
0
Attacker Value
Unknown

CVE-2018-19196

Disclosure Date: November 12, 2018 (last updated November 27, 2024)
An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type parameter to bypass the standard admin\controller\uploadfile.php restrictions on uploaded file types (jpg, jpeg, bmp, png, gif), as demonstrated by an admin/index.php?c=uploadfile&a=uploadify_upload&type=php URI.
0