CVE-2020-21236
- EPSS 0.14%
- Veröffentlicht 27.12.2021 23:15:08
- Zuletzt bearbeitet 21.11.2024 05:12:29
A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.
- EPSS 0.12%
- Veröffentlicht 12.08.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 05:08:37
Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd.
CVE-2020-18451
- EPSS 0.24%
- Veröffentlicht 12.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:36
Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in LabelAction.class.php.
CVE-2018-14831
- EPSS 0.26%
- Veröffentlicht 10.07.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 03:49:53
An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in the server via a crafted /admin.php?s=Tpl/Add/id/ URI.
CVE-2018-20571
- EPSS 0.33%
- Veröffentlicht 28.12.2018 16:29:05
- Zuletzt bearbeitet 21.11.2024 04:01:45
DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstrated by admin.php?s=Tpl/Add/id/.\Public\Config\config.ini.php to read the global configuration file.
CVE-2018-16331
- EPSS 0.18%
- Veröffentlicht 02.09.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:32
admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password.
- EPSS 0.26%
- Veröffentlicht 30.08.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:21
An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI.
CVE-2018-16238
- EPSS 2.15%
- Veröffentlicht 30.08.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:21
An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to the admin.php?s=/Tpl/Update.html URI. For example, this can update the Web/Tpl/default/head.html file.
CVE-2018-16239
- EPSS 0.44%
- Veröffentlicht 30.08.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:21
An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.
CVE-2018-15844
- EPSS 0.41%
- Veröffentlicht 25.08.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:33
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit.