Show filters
114 Total Results
Displaying 91-100 of 114
Sort by:
Attacker Value
Unknown
CVE-2018-18781
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
DedeCMS 5.7 SP2 allows XSS via the /member/uploads_select.php f or keyword parameter.
0
Attacker Value
Unknown
CVE-2018-18782
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.
0
Attacker Value
Unknown
CVE-2018-18608
Disclosure Date: October 23, 2018 (last updated November 27, 2024)
DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is used to display the page numbers list at the bottom of some templates, as demonstrated by the PATH_INFO to /member/index.php, /member/pm.php, /member/content_list.php, or /plus/feedback.php.
0
Attacker Value
Unknown
CVE-2018-18579
Disclosure Date: October 22, 2018 (last updated November 27, 2024)
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/pm.php folder parameter.
0
Attacker Value
Unknown
CVE-2018-18578
Disclosure Date: October 22, 2018 (last updated November 27, 2024)
DedeCMS 5.7 SP2 allows XSS via the plus/qrcode.php type parameter.
0
Attacker Value
Unknown
CVE-2018-16786
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php.
0
Attacker Value
Unknown
CVE-2018-16784
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring.
0
Attacker Value
Unknown
CVE-2018-16785
Disclosure Date: September 19, 2018 (last updated November 27, 2024)
XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell
0
Attacker Value
Unknown
CVE-2018-12046
Disclosure Date: June 08, 2018 (last updated November 26, 2024)
DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=newfile request with name and str parameters, as demonstrated by writing to a new .php file.
0
Attacker Value
Unknown
CVE-2018-12045
Disclosure Date: June 08, 2018 (last updated November 26, 2024)
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file.
0