|
245801
|
4.8 |
MEDIUM
Network
|
sem-cms
|
semcms
|
An XSS issue was discovered in SEMCMS 3.4 via the fifth text box to the admin/SEMCMS_Main.php URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18744
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245802
|
4.8 |
MEDIUM
Network
|
sem-cms
|
semcms
|
An XSS issue was discovered in SEMCMS 3.4 via the second text field to the admin/SEMCMS_Categories.php?pid=1&lgid=1 URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18743
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245803
|
8.8 |
HIGH
Network
|
sem-cms
|
semcms
|
A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-18742
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245804
|
4.8 |
MEDIUM
Network
|
sem-cms
|
semcms
|
An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Download.php?lgid=1 during editing.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18741
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245805
|
4.8 |
MEDIUM
Network
|
sem-cms
|
semcms
|
An XSS issue was discovered in SEMCMS 3.4 via the first input field to the admin/SEMCMS_Link.php?lgid=1 URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18740
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245806
|
4.8 |
MEDIUM
Network
|
sem-cms
|
semcms
|
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Products.php?lgid=1 Keywords field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18739
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245807
|
4.8 |
MEDIUM
Network
|
sem-cms
|
semcms
|
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Categories.php?pid=1&lgid=1 category_key parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18738
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245808
|
7.5 |
HIGH
Network
|
douchat
|
douchat
|
An XXE issue was discovered in Douchat 4.0.4 because Data\notify.php calls simplexml_load_string. This can also be used for SSRF.
|
CWE-611
XXE
|
CVE-2018-18737
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245809
|
5.4 |
MEDIUM
Network
|
catfish-cms
|
catfish_blog
|
An XSS issue was discovered in catfish blog 2.0.33, related to "write source code."
|
CWE-79
Cross-site Scripting
|
CVE-2018-18736
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245810
|
8.8 |
HIGH
Network
|
catfish-cms
|
catfish_blog
|
A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.
|
CWE-352
Origin Validation Error
|
CVE-2018-18735
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|