Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2024-11587

Disclosure Date: November 21, 2024 (last updated January 05, 2025)
A vulnerability was found in idcCMS 1.60. It has been classified as problematic. This affects the function GetCityOptionJs of the file /inc/classProvCity.php. The manipulation of the argument idName leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-40332

Disclosure Date: July 10, 2024 (last updated August 01, 2024)
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php?mudi=delRecord
Attacker Value
Unknown

CVE-2024-40334

Disclosure Date: July 10, 2024 (last updated October 12, 2024)
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?mudi=upFileDel&dataID=3
Attacker Value
Unknown

CVE-2024-40039

Disclosure Date: July 09, 2024 (last updated July 23, 2024)
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userGroup_deal.php?mudi=del
Attacker Value
Unknown

CVE-2024-40037

Disclosure Date: July 09, 2024 (last updated July 23, 2024)
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=del
Attacker Value
Unknown

CVE-2024-40034

Disclosure Date: July 09, 2024 (last updated July 23, 2024)
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userLevel_deal.php?mudi=del
Attacker Value
Unknown

CVE-2024-36669

Disclosure Date: June 05, 2024 (last updated June 28, 2024)
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.
Attacker Value
Unknown

CVE-2024-36668

Disclosure Date: June 05, 2024 (last updated June 28, 2024)
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=del
Attacker Value
Unknown

CVE-2024-36667

Disclosure Date: June 05, 2024 (last updated June 28, 2024)
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/idcProType_deal.php?mudi=add&nohrefStr=close
Attacker Value
Unknown

CVE-2024-36550

Disclosure Date: June 04, 2024 (last updated June 07, 2024)
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohrefStr=close