CVE-2023-3839 – DedeBIZ sys_sql_query.php sql injection
https://notcve.org/view.php?id=CVE-2023-3839
A vulnerability, which was classified as problematic, has been found in DedeBIZ 6.2.10. Affected by this issue is some unknown functionality of the file /admin/sys_sql_query.php. The manipulation of the argument sqlquery leads to sql injection. The attack may be launched remotely. The complexity of an attack is rather high. • https://github.com/TXPH/CVE/blob/main/sqli-report.pdf https://vuldb.com/?ctiid.235190 https://vuldb.com/?id.235190 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-3838 – DedeBIZ vote_edit.php cross site scripting
https://notcve.org/view.php?id=CVE-2023-3838
A vulnerability classified as problematic was found in DedeBIZ 6.2.10. Affected by this vulnerability is an unknown functionality of the file /admin/vote_edit.php. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/TXPH/CVE/blob/main/xss-report2.pdf https://vuldb.com/?ctiid.235189 https://vuldb.com/?id.235189 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-3837 – DedeBIZ sys_sql_query.php cross site scripting
https://notcve.org/view.php?id=CVE-2023-3837
A vulnerability classified as problematic has been found in DedeBIZ 6.2.10. Affected is an unknown function of the file /admin/sys_sql_query.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/TXPH/CVE/blob/main/xss-report.pdf https://vuldb.com/?ctiid.235188 https://vuldb.com/?id.235188 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-44120
https://notcve.org/view.php?id=CVE-2022-44120
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php. dedecmdv6 6.1.9 es vulnerable a la inyección SQL. a través de sys_sql_query.php. • https://gist.github.com/yinfei6/73295ac40b5b3fc0b55db58c17eecfda • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-43196
https://notcve.org/view.php?id=CVE-2022-43196
dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php. dedecmdv6 v6.1.9 es vulnerable a la eliminación arbitraria de archivos a través de file_manage_control.php. • https://gist.github.com/yinfei6/f6c8a9ac39afae45c3f2aa32a7f1b205 •