Page 7 of 143 results (0.010 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

16 Nov 2023 — Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form. Vulnerabilidad deCross-Site Request Forgery (CSRF) en DedeCMS v5.7 en la interfaz de administración de backend 110 a través de /catalog_add.php, permite a los atacantes crear páginas web manipuladas debido a la falta de verificación del valor del token del formulario envia... • https://github.com/thedarknessdied/dedecms/blob/main/v5.7_110-CSRF.md • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

13 Nov 2023 — DedeCMS v6.2 was discovered to contain a Cross-site Scripting (XSS) vulnerability via spec_add.php. Se descubrió que DedeCMS v6.2 contiene una vulnerabilidad de Cross-site Scripting (XSS) a través de spec_add.php. • https://github.com/CP1379767017/cms/blob/dreamcms_vul/dedevCMS/dedeCMS_XSS.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 3%CPEs: 1EXPL: 1

30 Sep 2023 — A vulnerability classified as critical was found in DedeCMS 5.7.111. This vulnerability affects the function AddMyAddon of the file album_add.php. The manipulation of the argument albumUploadFiles leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/Lamber-maybe/cve/blob/main/DedeCMS%20V5.7.111%20Remote%20Code%20Execution%20Vulnerability.md • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 1

28 Sep 2023 — An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file. Una vulnerabilidad de carga de archivos arbitrarios en dede/baidunews.php en DedeCMS 5.7.111 y versiones anteriores permite a los atacantes ejecutar código arbitrario cargando un archivo PHP manipulado. • https://github.com/zzq66/cve • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

17 Sep 2023 — A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepath leads to absolute path traversal. The associated identifier of this vulnerability is VDB-239863. Una vulnerabilidad ha sido encontrada en DedeCMS hasta 5.7.100 y clasificada como crítica. • https://github.com/bayuncao/DEDEcms • CWE-36: Absolute Path Traversal •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

12 Sep 2023 — DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php. DedeCMS 5.7.102 tiene una vulnerabilidad de Carga de Archivos a través de uploads/dede/module_make.php. • https://vulmon.com/vulnerabilitydetails?qid=CVE-2023-40784 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

04 Sep 2023 — A vulnerability classified as critical was found in DedeCMS 5.7.110. This vulnerability affects unknown code of the file /uploads/tags.php. The manipulation of the argument tag_alias leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/laoquanshi/cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

24 Aug 2023 — DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter. • https://github.com/DiliLearngent/BugReport/blob/main/php/DedeCMS/xss3.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

24 Aug 2023 — DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_edit.php via the votename and votenote parameters. • https://github.com/DiliLearngent/BugReport/blob/main/php/DedeCMS/xss2.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

24 Aug 2023 — DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title parameter. • https://github.com/DiliLearngent/BugReport/blob/main/php/DedeCMS/xss4.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •