Dbhcms Project

Dbhcms

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 24.08.2020 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:09:27

DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerabilit...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 24.08.2020 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:09:27

DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache operation. This vulnerability can be exploited to empty a table.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 24.08.2020 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:09:28

DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 24.08.2020 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:09:28

DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content.

Exploit
  • EPSS 0.63%
  • Veröffentlicht 24.08.2020 14:15:12
  • Zuletzt bearbeitet 21.11.2024 05:09:26

DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.