ShaoGongBra/dhcms

ShaoGongBra/dhcms

Releases0
鼎华云CMS,快速搭建企业网站

CVE History

CVEPublishedCVSS v3CVSS v2
8.1 HIGH5.5 MEDIUM

dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/del.

5.3 MEDIUM5 MEDIUM

An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path.

6.1 MEDIUM4.3 MEDIUM

A Cross SIte Scripting (XSS) vulnerability exists in Dhcms 2017-09-18 in guestbook via the message board, which could let a remote malicious user execute arbitrary code.

3.5 LOW

DhCms through 2017-09-18 has admin.php?r=admin/Index/index XSS.