Show filters
80 Total Results
Displaying 1-10 of 80
Sort by:
Attacker Value
Unknown

CVE-2024-7330

Disclosure Date: August 01, 2024 (last updated August 24, 2024)
A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the function curl_exec of the file /App/Core/Extend/Function/ydLib.php. The manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273253 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-7329

Disclosure Date: July 31, 2024 (last updated August 24, 2024)
A vulnerability, which was classified as critical, was found in YouDianCMS 7. Affected is an unknown function of the file /Public/ckeditor/plugins/multiimage/dialogs/image_upload.php. The manipulation of the argument files leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273252. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-7328

Disclosure Date: July 31, 2024 (last updated August 24, 2024)
A vulnerability, which was classified as problematic, has been found in YouDianCMS 7. This issue affects some unknown processing of the file /t.php?action=phpinfo. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273251. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-24291

Disclosure Date: February 06, 2024 (last updated February 14, 2024)
An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.
Attacker Value
Unknown

CVE-2024-24399

Disclosure Date: January 25, 2024 (last updated April 01, 2024)
An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php languages area.
Attacker Value
Unknown

CVE-2024-0414

Disclosure Date: January 11, 2024 (last updated January 19, 2024)
A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install.php. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250434 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-6772

Disclosure Date: December 13, 2023 (last updated December 19, 2023)
A vulnerability, which was classified as critical, was found in OTCMS 7.01. Affected is an unknown function of the file /admin/ind_backstage.php. The manipulation of the argument sqlContent leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247908.
Attacker Value
Unknown

CVE-2023-42322

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information.
Attacker Value
Unknown

CVE-2023-42321

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files.
Attacker Value
Unknown

CVE-2023-40953

Disclosure Date: September 08, 2023 (last updated October 08, 2023)
icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).