Page 30 of 201 results (0.005 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter. WUZHI CMS 4.1.0 tiene Cross-Site Scripting (XSS) mediante el parámetro form[statcode] en index.php?m=coref=setv=basic. • https://github.com/wuzhicms/wuzhicms/issues/148 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

WUZHI CMS 4.1.0 has XSS via the index.php?m=link&f=index&v=add form[remark] parameter. WUZHI CMS 4.1.0 tiene Cross-Site Scripting (XSS) mediante el parámetro form[remark] en index.php?m=linkf=indexv=add. • https://github.com/wuzhicms/wuzhicms/issues/147 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

A SQL injection was discovered in /coreframe/app/admin/copyfrom.php in WUZHI CMS 4.1.0 via the index.php?m=core&f=copyfrom&v=listing keywords parameter. Se ha descubierto una inyección SQL en /coreframe/app/admin/copyfrom.php en WUZHI CMS 4.1.0 mediante el parámetro keywords en index.php?m=coref=copyfromv=listing. • https://github.com/wuzhicms/wuzhicms/issues/149 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

A SQL injection was discovered in /coreframe/app/admin/pay/admin/index.php in WUZHI CMS 4.1.0 via the index.php?m=pay&f=index&v=listing keyValue parameter. Se ha descubierto una inyección SQL en /coreframe/app/admin/pay/admin/index.php en WUZHI CMS 4.1.0 mediante el parámetro keyValue en index.php?m=payf=indexv=listing. • https://github.com/wuzhicms/wuzhicms/issues/150 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the Author field of the "Leave a Comment" screen. Se ha descubierto un problema en Victor CMS hasta el 10/05/2018. Existe Cross-Site Scripting (XSS) mediante el campo Author de la pantalla "Leave a Comment". • https://github.com/VictorAlagwu/CMSsite/issues/2 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •