Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2018-14729
Disclosure Date: May 22, 2019 (last updated November 27, 2024)
The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.
0
Attacker Value
Unknown
CVE-2018-20424
Disclosure Date: December 24, 2018 (last updated November 27, 2024)
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp request to plugin.php.
0
Attacker Value
Unknown
CVE-2018-20423
Disclosure Date: December 24, 2018 (last updated November 27, 2024)
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-existing wxopenid value to the plugin.php ac=wxregister query string.
0
Attacker Value
Unknown
CVE-2018-20422
Disclosure Date: December 24, 2018 (last updated November 27, 2024)
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_wechatmp to gain login access to an account via a plugin.php ac=wxregister request (the attacker does not have control over which account will be accessed).
0
Attacker Value
Unknown
CVE-2018-18084
Disclosure Date: October 09, 2018 (last updated November 27, 2024)
An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.
0
Attacker Value
Unknown
CVE-2018-18083
Disclosure Date: October 09, 2018 (last updated November 27, 2024)
An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.
0
Attacker Value
Unknown
CVE-2009-3185
Disclosure Date: September 15, 2009 (last updated October 04, 2023)
SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQL commands via the fmid parameter in a view action.
0
Attacker Value
Unknown
CVE-2008-6958
Disclosure Date: August 12, 2009 (last updated October 04, 2023)
wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter.
0
Attacker Value
Unknown
CVE-2008-3554
Disclosure Date: August 08, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parameter in a search action.
0