Latest sem-cms semcms Vulnerabilities

SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.
Sem-cms Semcms=4.8
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
Sem-cms Semcms=4.8
SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existing application to inject malicious SQL commands into the back...
Sem-cms Semcms=3.9
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
Sem-cms Semcms=3.9
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
Sem-cms Semcms=1.5
Sem-cms Semcms=3.7
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows attackers to execute arbitrary code via uploading a cra...
Sem-cms Semcms=4.2
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
Sem-cms Semcms=1.1
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
Sem-cms Semcms=1.1
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
Sem-cms Semcms=1.1
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
Sem-cms Semcms=1.1
SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.
Sem-cms Semcms=1.1
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
Sem-cms Semcms=1.1
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
Sem-cms Semcms=1.2
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
Sem-cms Semcms=1.1
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
Sem-cms Semcms=1.1
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
Sem-cms Semcms=1.1
A vulnerability classified as critical has been found in SEMCMS. This affects an unknown part of the file Ant_Check.php. The manipulation of the argument DID leads to sql injection. It is possible to ...
Sem-cms Semcms
The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext through a SQL query.
Sem-cms Semcms=3.8
A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.
Sem-cms Semcms=3.8
An issue was discovered in SEMCMS 3.8. SEMCMS_Inquiry.php allows AID[] SQL Injection because the class.phpmailer.php inject_check_sql protection mechanism is incomplete.
Sem-cms Semcms=3.8
SEMCMS 3.5 has XSS via the first text box to the SEMCMS_Main.php URI.
Sem-cms Semcms=3.5
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.
Sem-cms Semcms=3.4
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexkey parameter.
Sem-cms Semcms=3.4
XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter.
Sem-cms Semcms=3.4
An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Menu.php?lgid=1 during editing.
Sem-cms Semcms=3.4
An XSS issue was discovered in SEMCMS 3.4 via the fifth text box to the admin/SEMCMS_Main.php URI.
Sem-cms Semcms=3.4
An XSS issue was discovered in SEMCMS 3.4 via the second text field to the admin/SEMCMS_Categories.php?pid=1&lgid=1 URI.
Sem-cms Semcms=3.4
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Products.php?lgid=1 Keywords field.
Sem-cms Semcms=3.4
An XSS issue was discovered in SEMCMS 3.4 via the first input field to the admin/SEMCMS_Link.php?lgid=1 URI.
Sem-cms Semcms=3.4
A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.
Sem-cms Semcms=3.4
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Categories.php?pid=1&lgid=1 category_key parameter.
Sem-cms Semcms=3.4
An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Download.php?lgid=1 during editing.
Sem-cms Semcms=3.4

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203