40 results (0.002 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

05 Jul 2024 — An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php. Se descubrió un problema en SeaCMS &lt;=12.9 que permite a atacantes remotos ejecutar código arbitrario a través de admin_ping.php. • https://github.com/pysnow1/vul_discovery/blob/main/SeaCMS/SeaCMS%20v12.9%20admin_ping.php%20RCE.md • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

24 Oct 2023 — An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component. Un problema en SeaCMS v.12.9 permite a un atacante ejecutar comandos arbitrarios a través del componente admin_safe.php. • http://seacms.com • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 8.3EPSS: 0%CPEs: 1EXPL: 1

10 Oct 2023 — An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component. Un problema en SeaCMS v.12.8 permite a un atacante ejecutar código arbitrario a través del componente admin_Weixin.php. • https://blog.csdn.net/2301_79997870/article/details/133661890?spm=1001.2014.3001.5502 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 8.5EPSS: 0%CPEs: 1EXPL: 0

10 Oct 2023 — An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_template.php component. Un problema en SeaCMS v.12.8 permite a un atacante ejecutar código arbitrario a través del componente admin_template.php. • https://blog.csdn.net/2301_79997870/article/details/133661890?spm=1001.2014.3001.5502 •

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 1

10 Oct 2023 — An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component. Un problema en SeaCMS v.12.8 permite a un atacante ejecutar código arbitrario a través del componente admin_notify.php. • https://blog.csdn.net/2301_79997870/article/details/133365547?spm=1001.2014.3001.5501 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

26 Sep 2023 — SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file. SeaCMS v12.8 tiene una vulnerabilidad de escritura de código arbitrario en el archivo /jxz7g2/admin_ping.php. • https://blog.csdn.net/weixin_51394168/article/details/132817842 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

25 Sep 2023 — A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account. Un Cross-Site Request Forgery (CSRF) en admin_manager.php de Seacms hasta v12.8 permite a los atacantes agregar arbitrariamente una cuenta de administrador. • http://seacms.com • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

06 Jul 2023 — A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. • https://github.com/seacms-com/seacms/issues/24 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

06 Jul 2023 — A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. • https://github.com/seacms-com/seacms/issues/25 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 1

27 May 2023 — A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file member.php of the component Picture Upload Handler. The manipulation of the argument oldpic leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/xryj920/CVE/blob/main/DEL.md • CWE-404: Improper Resource Shutdown or Release •