Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2024-0416

Disclosure Date: January 11, 2024 (last updated January 19, 2024)
A vulnerability, which was classified as critical, has been found in DeShang DSMall up to 5.0.3. Affected by this issue is some unknown functionality of the file application/home/controller/MemberAuth.php. The manipulation of the argument file_name leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250436.
Attacker Value
Unknown

CVE-2024-0415

Disclosure Date: January 11, 2024 (last updated January 19, 2024)
A vulnerability classified as critical was found in DeShang DSMall up to 6.1.0. Affected by this vulnerability is an unknown functionality of the file application/home/controller/TaobaoExport.php of the component Image URL Handler. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250435.
Attacker Value
Unknown

CVE-2024-0411

Disclosure Date: January 11, 2024 (last updated January 19, 2024)
A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown part of the file public/install.php of the component HTTP GET Request Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250431.
Attacker Value
Unknown

CVE-2018-9307

Disclosure Date: April 04, 2018 (last updated November 26, 2024)
dsmall v20180320 allows XSS via the pdr_sn parameter to public/index.php/home/predeposit/index.html.
0
Attacker Value
Unknown

CVE-2018-9015

Disclosure Date: March 25, 2018 (last updated November 26, 2024)
dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box).
0
Attacker Value
Unknown

CVE-2018-9017

Disclosure Date: March 25, 2018 (last updated November 26, 2024)
dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI.
0
Attacker Value
Unknown

CVE-2018-9016

Disclosure Date: March 25, 2018 (last updated November 26, 2024)
dsmall v20180320 allows XSS via the main page search box at the public/index.php/home URI.
0
Attacker Value
Unknown

CVE-2018-9014

Disclosure Date: March 25, 2018 (last updated November 26, 2024)
dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request.
0
Attacker Value
Unknown

CVE-2018-8906

Disclosure Date: March 22, 2018 (last updated November 26, 2024)
dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/2.html.
0