CVE-2020-18114
- EPSS 1.14%
- Veröffentlicht 27.08.2021 21:15:06
- Zuletzt bearbeitet 21.11.2024 05:08:23
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
CVE-2020-18917
- EPSS 0.2%
- Veröffentlicht 24.08.2021 20:15:09
- Zuletzt bearbeitet 21.11.2024 05:08:52
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
CVE-2020-22198
- EPSS 0.86%
- Veröffentlicht 16.06.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:13:09
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
CVE-2020-16632
- EPSS 0.36%
- Veröffentlicht 15.05.2021 00:15:07
- Zuletzt bearbeitet 21.11.2024 05:07:12
A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.
CVE-2021-32073
- EPSS 0.37%
- Veröffentlicht 15.05.2021 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:06:48
DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution.
CVE-2020-27533
- EPSS 0.73%
- Veröffentlicht 22.10.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:21:19
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.
CVE-2015-4553
- EPSS 38.52%
- Veröffentlicht 06.01.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 02:31:19
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
CVE-2019-10014
- EPSS 0.11%
- Veröffentlicht 24.03.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:13
In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users via a modified id parameter, because the key parameter is not properly validated.
CVE-2019-8933
- EPSS 24.35%
- Veröffentlicht 19.02.2019 02:29:00
- Zuletzt bearbeitet 21.11.2024 04:50:41
In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execute this file, via this sequence of steps: visiting the management page, clicking on the template, cli...
CVE-2019-8362
- EPSS 0.21%
- Veröffentlicht 16.02.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:49:45
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=save&formzip=1 request with a ZIP archive that contains a file such as "1.jpg.php" (because input valid...