Douco

Douphp

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.01%
  • Veröffentlicht 09.02.2026 09:32:07
  • Zuletzt bearbeitet 27.02.2026 18:10:01

A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File Handler. Such manipulation of the argument sql_filename leads to unrestricted upload. The attack can ...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 06.02.2025 17:15:20
  • Zuletzt bearbeitet 03.07.2025 01:16:45

Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php

Exploit
  • EPSS 0.1%
  • Veröffentlicht 18.08.2024 23:15:04
  • Zuletzt bearbeitet 21.08.2024 12:30:34

A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue is some unknown functionality of the file /admin/system.php of the component Favicon Handler. The manipulation of the argument si...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 13.01.2023 00:15:09
  • Zuletzt bearbeitet 08.04.2025 14:15:28

A cross-site scripting (XSS) vulnerability in the /admin/article_category.php component of DouPHP v1.7 20221118 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the description parameter.

Exploit
  • EPSS 0.43%
  • Veröffentlicht 30.03.2022 12:15:08
  • Zuletzt bearbeitet 21.11.2024 06:49:52

DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which will lead to JavaScript code execution.

  • EPSS 0.48%
  • Veröffentlicht 25.03.2022 16:15:09
  • Zuletzt bearbeitet 21.11.2024 06:52:22

A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file.

  • EPSS 0.24%
  • Veröffentlicht 08.12.2021 04:15:06
  • Zuletzt bearbeitet 21.11.2024 06:21:22

DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php.

Exploit
  • EPSS 0.38%
  • Veröffentlicht 03.06.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:23:05

In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/DyyyymmddThhmmss.sql filenames.

Exploit
  • EPSS 0.37%
  • Veröffentlicht 28.12.2018 16:29:05
  • Zuletzt bearbeitet 21.11.2024 04:01:44

An issue was discovered in DouCo DouPHP 1.5 20181221. It allows full path disclosure in "Smarty error: unable to read resource" error messages for a crafted installation page.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 28.12.2018 16:29:05
  • Zuletzt bearbeitet 21.11.2024 04:01:44

An issue was discovered in DouCo DouPHP 1.5 20181221. \install\index.php allows a reload of the product in opportunistic circumstances in which install.lock cannot be read.