Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2023-5015
Disclosure Date: September 17, 2023 (last updated October 08, 2023)
A vulnerability was found in UCMS 1.4.7. It has been classified as problematic. Affected is an unknown function of the file ajax.php?do=strarraylist. The manipulation of the argument strdefault leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239856.
0
Attacker Value
Unknown
CVE-2020-24000
Disclosure Date: November 03, 2021 (last updated February 23, 2025)
SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.
0
Attacker Value
Unknown
CVE-2020-20781
Disclosure Date: September 29, 2021 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields.
0
Attacker Value
Unknown
CVE-2019-12251
Disclosure Date: May 21, 2019 (last updated November 27, 2024)
sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter.
0
Attacker Value
Unknown
CVE-2018-20597
Disclosure Date: December 30, 2018 (last updated November 27, 2024)
UCMS 1.4.7 has XSS via the dir parameter in an index.php sadmin_fileedit action.
0
Attacker Value
Unknown
CVE-2018-20600
Disclosure Date: December 30, 2018 (last updated November 27, 2024)
sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action.
0
Attacker Value
Unknown
CVE-2018-20598
Disclosure Date: December 30, 2018 (last updated November 27, 2024)
UCMS 1.4.7 has ?do=user_addpost CSRF.
0
Attacker Value
Unknown
CVE-2018-20601
Disclosure Date: December 30, 2018 (last updated November 27, 2024)
UCMS 1.4.7 has XSS via the description parameter in an index.php list_editpost action.
0
Attacker Value
Unknown
CVE-2018-20599
Disclosure Date: December 30, 2018 (last updated November 27, 2024)
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
0
Attacker Value
Unknown
CVE-2018-19437
Disclosure Date: November 22, 2018 (last updated November 27, 2024)
UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.
0