|
245781
|
9.8 |
CRITICAL
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php.
|
CWE-89
SQL Injection
|
CVE-2018-18789
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245782
|
7.2 |
HIGH
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.)
|
CWE-89
SQL Injection
|
CVE-2018-18788
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245783
|
9.8 |
CRITICAL
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.
|
CWE-89
SQL Injection
|
CVE-2018-18787
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245784
|
9.8 |
CRITICAL
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.
|
CWE-89
SQL Injection
|
CVE-2018-18786
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245785
|
9.8 |
CRITICAL
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.
|
CWE-89
SQL Injection
|
CVE-2018-18785
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245786
|
7.2 |
HIGH
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This needs an admin user login.)
|
CWE-89
SQL Injection
|
CVE-2018-18784
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245787
|
6.1 |
MEDIUM
Network
|
sem-cms
|
semcms
|
XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18783
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245788
|
6.1 |
MEDIUM
Network
|
dedecms
|
dedecms
|
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18782
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245789
|
6.1 |
MEDIUM
Network
|
dedecms
|
dedecms
|
DedeCMS 5.7 SP2 allows XSS via the /member/uploads_select.php f or keyword parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18781
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245790
|
6.5 |
MEDIUM
Network
|
acme
|
mini-httpd
|
ACME mini_httpd before 1.30 lets remote users read arbitrary files.
|
CWE-200
Information Exposure
|
CVE-2018-18778
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|