jsjbcyber/bug_report

jsjbcyber/bug_report

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL10 HIGH

Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.

6.1 MEDIUM4.3 MEDIUM

Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.

9.8 CRITICAL7.5 HIGH

Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.

9.8 CRITICAL7.5 HIGH

Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.

9.8 CRITICAL7.5 HIGH

Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.

9.8 CRITICAL7.5 HIGH

Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.

9.8 CRITICAL7.5 HIGH

Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.

9.8 CRITICAL7.5 HIGH

Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.

9.8 CRITICAL7.5 HIGH

Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements.

7.5 HIGH5 MEDIUM

Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information through SQL injection statements.

9.8 CRITICAL7.5 HIGH

eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.

9.8 CRITICAL7.5 HIGH

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.

9.8 CRITICAL7.5 HIGH

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.

9.8 CRITICAL7.5 HIGH

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.

9.8 CRITICAL7.5 HIGH

eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.

9.1 CRITICAL6.4 MEDIUM

An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files.