Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2023-5015

Disclosure Date: September 17, 2023 (last updated October 08, 2023)
A vulnerability was found in UCMS 1.4.7. It has been classified as problematic. Affected is an unknown function of the file ajax.php?do=strarraylist. The manipulation of the argument strdefault leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239856.
Attacker Value
Unknown

CVE-2020-24000

Disclosure Date: November 03, 2021 (last updated February 23, 2025)
SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.
Attacker Value
Unknown

CVE-2020-20781

Disclosure Date: September 29, 2021 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields.
Attacker Value
Unknown

CVE-2019-12251

Disclosure Date: May 21, 2019 (last updated November 27, 2024)
sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter.
0
Attacker Value
Unknown

CVE-2018-20597

Disclosure Date: December 30, 2018 (last updated November 27, 2024)
UCMS 1.4.7 has XSS via the dir parameter in an index.php sadmin_fileedit action.
0
Attacker Value
Unknown

CVE-2018-20600

Disclosure Date: December 30, 2018 (last updated November 27, 2024)
sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action.
0
Attacker Value
Unknown

CVE-2018-20598

Disclosure Date: December 30, 2018 (last updated November 27, 2024)
UCMS 1.4.7 has ?do=user_addpost CSRF.
0
Attacker Value
Unknown

CVE-2018-20601

Disclosure Date: December 30, 2018 (last updated November 27, 2024)
UCMS 1.4.7 has XSS via the description parameter in an index.php list_editpost action.
0
Attacker Value
Unknown

CVE-2018-20599

Disclosure Date: December 30, 2018 (last updated November 27, 2024)
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
0
Attacker Value
Unknown

CVE-2018-19437

Disclosure Date: November 22, 2018 (last updated November 27, 2024)
UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.
0