CVE-2026-2226
- EPSS 0.01%
- Veröffentlicht 09.02.2026 09:32:07
- Zuletzt bearbeitet 27.02.2026 18:10:01
A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File Handler. Such manipulation of the argument sql_filename leads to unrestricted upload. The attack can ...
CVE-2024-57599
- EPSS 0.13%
- Veröffentlicht 06.02.2025 17:15:20
- Zuletzt bearbeitet 03.07.2025 01:16:45
Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php
CVE-2024-7917
- EPSS 0.1%
- Veröffentlicht 18.08.2024 23:15:04
- Zuletzt bearbeitet 21.08.2024 12:30:34
A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue is some unknown functionality of the file /admin/system.php of the component Favicon Handler. The manipulation of the argument si...
CVE-2022-46438
- EPSS 0.21%
- Veröffentlicht 13.01.2023 00:15:09
- Zuletzt bearbeitet 08.04.2025 14:15:28
A cross-site scripting (XSS) vulnerability in the /admin/article_category.php component of DouPHP v1.7 20221118 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the description parameter.
CVE-2022-24131
- EPSS 0.43%
- Veröffentlicht 30.03.2022 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:49:52
DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which will lead to JavaScript code execution.
CVE-2022-25574
- EPSS 0.48%
- Veröffentlicht 25.03.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:52:22
A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file.
CVE-2021-3370
- EPSS 0.24%
- Veröffentlicht 08.12.2021 04:15:06
- Zuletzt bearbeitet 21.11.2024 06:21:22
DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php.
CVE-2019-12564
- EPSS 0.38%
- Veröffentlicht 03.06.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:23:05
In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/DyyyymmddThhmmss.sql filenames.
CVE-2018-20566
- EPSS 0.37%
- Veröffentlicht 28.12.2018 16:29:05
- Zuletzt bearbeitet 21.11.2024 04:01:44
An issue was discovered in DouCo DouPHP 1.5 20181221. It allows full path disclosure in "Smarty error: unable to read resource" error messages for a crafted installation page.
CVE-2018-20567
- EPSS 0.27%
- Veröffentlicht 28.12.2018 16:29:05
- Zuletzt bearbeitet 21.11.2024 04:01:44
An issue was discovered in DouCo DouPHP 1.5 20181221. \install\index.php allows a reload of the product in opportunistic circumstances in which install.lock cannot be read.