İçeriğe atla
Noroxi

dbhcms project kayıtları

dbhcms project üreticisine ait 15 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

15 kayıt
  • CVE-2020-19889
    35İzleyin

    DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.

    YüksekCVSS 8,8İstismar yokEPSS %1

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19886
    32İzleyin

    DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu.

    YüksekCVSS 8,1İstismar yokEPSS %0

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19878
    30İzleyin

    DBHcms v1.2.0 has a sensitive information leaks vulnerability as there is no security access control in /dbhcms/ext/news/ext.news.be.php, A

    YüksekCVSS 7,5İstismar yokEPSS %2

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19891
    28İzleyin

    DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename and $_POST['tinymce_co

    YüksekCVSS 7,2İstismar yokEPSS %1

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19880
    24İzleyin

    DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A remote unauthentica

    OrtaCVSS 6,1İstismar yokEPSS %1

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19879
    24İzleyin

    DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcms\page.php line 107,

    OrtaCVSS 6,1İstismar yokEPSS %1

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19888
    23İzleyin

    DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache o

    OrtaCVSS 5,9İstismar yokEPSS %1

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19877
    22İzleyin

    DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/.

    OrtaCVSS 5,3İstismar yokEPSS %2

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19890
    19İzleyin

    DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter func

    OrtaCVSS 4,9İstismar yokEPSS %1

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19885
    19İzleyin

    DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhc

    OrtaCVSS 4,8İstismar yokEPSS %1

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19881
    19İzleyin

    DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 for $_GET['return_nam

    OrtaCVSS 4,8İstismar yokEPSS %1

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19887
    19İzleyin

    DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable

    OrtaCVSS 4,8İstismar yokEPSS %1

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19883
    19İzleyin

    DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user_login, A remot

    OrtaCVSS 4,8İstismar yokEPSS %1

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19882
    19İzleyin

    DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in dbhcms\mod\mod.menu

    OrtaCVSS 4,8İstismar yokEPSS %1

    dbhcms project · dbhcms24 Ağu 2020

  • CVE-2020-19884
    19İzleyin

    DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line 119.

    OrtaCVSS 4,8İstismar yokEPSS %1

    dbhcms project · dbhcms24 Ağu 2020