Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2020-35339
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server permissions and control the server.
0
Attacker Value
Unknown
CVE-2019-11374
Disclosure Date: April 20, 2019 (last updated November 27, 2024)
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
0
Attacker Value
Unknown
CVE-2019-10684
Disclosure Date: April 01, 2019 (last updated November 27, 2024)
Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Admin&c=config&a=edit site_domain parameter.
0