Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2020-20601

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
Attacker Value
Unknown

CVE-2018-19897

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
ThinkCMF X2.2.2 has SQL Injection via the function _listorders() in AdminbaseController.class.php and is exploitable with the manager privilege via the listorders[key][1] parameter in a Link listorders action.
0
Attacker Value
Unknown

CVE-2018-19894

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is exploitable with the manager privilege via the ids[] parameter in a commentadmin action.
0
Attacker Value
Unknown

CVE-2018-19896

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
ThinkCMF X2.2.2 has SQL Injection via the function delete() in SlideController.class.php and is exploitable with the manager privilege via the ids[] parameter in a slide action.
0
Attacker Value
Unknown

CVE-2018-19895

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
ThinkCMF X2.2.2 has SQL Injection via the function edit_post() in NavController.class.php and is exploitable with the manager privilege via the parentid parameter in a nav action.
0
Attacker Value
Unknown

CVE-2018-19898

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
ThinkCMF X2.2.2 has SQL Injection via the method edit_post in ArticleController.class.php and is exploitable by normal authenticated users via the post[id][1] parameter in an article edit_post action.
0