Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2021-35261
Disclosure Date: February 17, 2023 (last updated October 08, 2023)
File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.
0
Attacker Value
Unknown
CVE-2018-11413
Disclosure Date: May 24, 2018 (last updated November 26, 2024)
An issue was discovered in BearAdmin 0.5. Remote attackers can download arbitrary files via /admin/databack/download.html?name= directory traversal sequences, as demonstrated by name=../application/database.php to read the MySQL credentials in the configuration.
0
Attacker Value
Unknown
CVE-2018-11414
Disclosure Date: May 24, 2018 (last updated November 26, 2024)
An issue was discovered in BearAdmin 0.5. There is admin/admin_log/index.html?user_id= SQL injection because admin\controller\AdminLog.php constructs a MySQL query improperly.
0