CVE-2018-12498
- EPSS 0.25%
- Veröffentlicht 15.06.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:20
spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php.
CVE-2018-10250
- EPSS 0.21%
- Veröffentlicht 20.04.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:06
iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search.
CVE-2018-10222
- EPSS 0.14%
- Veröffentlicht 19.04.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:02
An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?app=article_category&do=save&frame=iPHP.
CVE-2018-10117
- EPSS 0.12%
- Veröffentlicht 16.04.2018 09:58:10
- Zuletzt bearbeitet 21.11.2024 03:40:51
An issue was discovered in idreamsoft iCMS V7.0.7. There is a CSRF vulnerability that can add an admin account via admincp.php?app=members&do=save&frame=iPHP.
CVE-2018-9922
- EPSS 0.23%
- Veröffentlicht 10.04.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:51
An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weixin.class.php pathname.
CVE-2018-9925
- EPSS 0.21%
- Veröffentlicht 10.04.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:51
An issue was discovered in idreamsoft iCMS through 7.0.7. XSS exists via the nickname field in an admincp.php?app=user&do=save&frame=iPHP request.
CVE-2018-9924
- EPSS 0.25%
- Veröffentlicht 10.04.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:51
An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp.php?app=tag&do=save&frame=iPHP request.
CVE-2018-9923
- EPSS 0.14%
- Veröffentlicht 10.04.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:51
An issue was discovered in idreamsoft iCMS through 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an article via an app=article&do=save&frame=iPHP request.