millken/doyocms

millken/doyocms

Releases0
Stars5
DOYO通用建站程序,PHP免费开源企业CMS建站系统,官方网站:http://wdoyo.com

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the upload file type parameter.

8.8 HIGH

Cross Site Request Forgery vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the background system settings.

9.8 CRITICAL7.5 HIGH

SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attribute parameter.

9.8 CRITICAL7.5 HIGH

Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code.

8.8 HIGH6.5 MEDIUM

A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the orders[] parameter.

3.5 LOW

An issue was discovered in DOYO (aka doyocms) 2.3 through 2015-05-06. It has admin.php XSS.

6.8 MEDIUM

An issue was discovered in DOYO (aka doyocms) 2.3(20140425 update). There is a CSRF vulnerability that can add a super administrator account via admin.php?c=a_adminuser&a=add&run=1.