• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-94

CVE-2018-9848

February 26, 2023 by

In Gxlcms QY v1.0.0713, the upload function in LibLibActionAdminUploadAction.class.php allows remote attackers to execute arbitrary PHP code by first using an Admin-Admin-Configsave request to change the config[upload_class] value from jpg,gif,png,jpeg to jpg,gif,png,jpeg,php and then making an Admin-Upload-Upload request.

CVE-2018-9174

February 26, 2023 by

sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker’s control.

CVE-2018-9175

February 26, 2023 by

DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within the database is accessible to uploads/dede/sys_cache_up.php.

CVE-2018-9113

February 26, 2023 by

Centers for Disease Control and Prevention MicrobeTRACE 0.1.12 allows remote attackers to execute arbitrary code, related to code injection via a crafted CSV file with an initial ‘><script type="text/javascript" src=' line. Fix released on 2018-03-29.

CVE-2018-8966

February 26, 2023 by

An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.

CVE-2018-8974

February 26, 2023 by

Centers for Disease Control and Prevention MicrobeTRACE 0.1.11 allows remote attackers to execute arbitrary code, related to code injection via a crafted CSV file with an initial ‘Source<script type="text/javascript" src=' line. Fix released on 2018-03-28.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 112
  • Go to page 113
  • Go to page 114
  • Go to page 115
  • Go to page 116
  • Interim pages omitted …
  • Go to page 225
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE