Show filters
52 Total Results
Displaying 1-10 of 52
Sort by:
Attacker Value
Unknown
CVE-2025-0480
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-10505
Disclosure Date: October 30, 2024 (last updated November 07, 2024)
A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Initially two separate issues were created by the researcher for the different function calls. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-2016
Disclosure Date: March 21, 2024 (last updated March 21, 2024)
A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the argument sitename leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-255270 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-2015
Disclosure Date: March 21, 2024 (last updated March 21, 2024)
A vulnerability, which was classified as critical, has been found in ZhiCms 4.0. This issue affects the function getindexdata of the file app/index/controller/mcontroller.php. The manipulation of the argument key leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-255269 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-0603
Disclosure Date: January 16, 2024 (last updated January 24, 2024)
A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250839.
0
Attacker Value
Unknown
CVE-2023-51154
Disclosure Date: January 04, 2024 (last updated January 11, 2024)
Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.
0
Attacker Value
Unknown
CVE-2023-50692
Disclosure Date: December 28, 2023 (last updated January 05, 2024)
File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.
0
Attacker Value
Unknown
CVE-2023-46482
Disclosure Date: November 01, 2023 (last updated November 09, 2023)
SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.
0
Attacker Value
Unknown
CVE-2023-43836
Disclosure Date: October 02, 2023 (last updated October 09, 2023)
There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information
0
Attacker Value
Unknown
CVE-2020-36037
Disclosure Date: August 11, 2023 (last updated October 08, 2023)
An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.
0