Page 3 of 17 results (0.007 seconds)

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

A vulnerability, which was classified as problematic, has been found in DedeBIZ 6.2.10. Affected by this issue is some unknown functionality of the file /admin/sys_sql_query.php. The manipulation of the argument sqlquery leads to sql injection. The attack may be launched remotely. The complexity of an attack is rather high. • https://github.com/TXPH/CVE/blob/main/sqli-report.pdf https://vuldb.com/?ctiid.235190 https://vuldb.com/?id.235190 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

A vulnerability classified as problematic was found in DedeBIZ 6.2.10. Affected by this vulnerability is an unknown functionality of the file /admin/vote_edit.php. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/TXPH/CVE/blob/main/xss-report2.pdf https://vuldb.com/?ctiid.235189 https://vuldb.com/?id.235189 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

A vulnerability classified as problematic has been found in DedeBIZ 6.2.10. Affected is an unknown function of the file /admin/sys_sql_query.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/TXPH/CVE/blob/main/xss-report.pdf https://vuldb.com/?ctiid.235188 https://vuldb.com/?id.235188 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php. dedecmdv6 6.1.9 es vulnerable a la inyección SQL. a través de sys_sql_query.php. • https://gist.github.com/yinfei6/73295ac40b5b3fc0b55db58c17eecfda • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 0

dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php. dedecmdv6 v6.1.9 es vulnerable a la eliminación arbitraria de archivos a través de file_manage_control.php. • https://gist.github.com/yinfei6/f6c8a9ac39afae45c3f2aa32a7f1b205 •