Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2020-21236
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.
0
Attacker Value
Unknown
CVE-2020-18458
Disclosure Date: August 12, 2021 (last updated February 23, 2025)
Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd.
0
Attacker Value
Unknown
CVE-2020-18451
Disclosure Date: August 12, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in LabelAction.class.php.
0
Attacker Value
Unknown
CVE-2018-14831
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in the server via a crafted /admin.php?s=Tpl/Add/id/ URI.
0
Attacker Value
Unknown
CVE-2018-20571
Disclosure Date: December 28, 2018 (last updated November 27, 2024)
DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstrated by admin.php?s=Tpl/Add/id/.\Public\Config\config.ini.php to read the global configuration file.
0
Attacker Value
Unknown
CVE-2018-16331
Disclosure Date: September 02, 2018 (last updated November 27, 2024)
admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password.
0
Attacker Value
Unknown
CVE-2018-16238
Disclosure Date: August 30, 2018 (last updated November 27, 2024)
An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to the admin.php?s=/Tpl/Update.html URI. For example, this can update the Web/Tpl/default/head.html file.
0
Attacker Value
Unknown
CVE-2018-16237
Disclosure Date: August 30, 2018 (last updated November 27, 2024)
An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI.
0
Attacker Value
Unknown
CVE-2018-16239
Disclosure Date: August 30, 2018 (last updated November 27, 2024)
An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.
0
Attacker Value
Unknown
CVE-2018-15844
Disclosure Date: August 25, 2018 (last updated November 27, 2024)
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit.
0