Show filters
142 Total Results
Displaying 1-10 of 142
Sort by:
Attacker Value
High

CVE-2020-7357

Disclosure Date: April 06, 2020 (last updated February 21, 2025)
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.
Attacker Value
Unknown

CVE-2024-13193

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file SEMCMS_Images.php of the component Image Library Management Page. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2024-44921

Disclosure Date: September 03, 2024 (last updated February 26, 2025)
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
Attacker Value
Unknown

CVE-2024-44920

Disclosure Date: September 03, 2024 (last updated February 26, 2025)
A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter.
Attacker Value
Unknown

CVE-2024-44683

Disclosure Date: August 30, 2024 (last updated February 26, 2025)
Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.
Attacker Value
Unknown

CVE-2024-44919

Disclosure Date: August 29, 2024 (last updated February 26, 2025)
A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter.
Attacker Value
Unknown

CVE-2024-41444

Disclosure Date: August 26, 2024 (last updated February 26, 2025)
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
Attacker Value
Unknown

CVE-2024-7729

Disclosure Date: August 14, 2024 (last updated February 26, 2025)
The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CGI files.
0
Attacker Value
Unknown

CVE-2024-7728

Disclosure Date: August 14, 2024 (last updated February 26, 2025)
The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands into the specific parameter and execute them on the remote server.
0
Attacker Value
Unknown

CVE-2024-7163

Disclosure Date: July 28, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as problematic, was found in SeaCMS 12.9. This affects an unknown part of the file /js/player/dmplayer/player/index.php. The manipulation of the argument color/vid/url leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272577 was assigned to this vulnerability.