SQL injection vulnerability in mod/gallery/ajax/gallerydata.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albums parameter.
Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/controllers/fm.php. The attacker needs to use admin/mediaupload and fm/move.
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php.
An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via adminping.php.
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /adminreslib.php.
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function EbakRepPathFiletext().
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.
SeaCMS v13.3 has a SQL injection vulnerability in the component admintempvideo.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via a crafted request.
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component adminmanager.php.
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admintopic.php.
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admincommentnews.php.
Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the emailoutgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload.
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component adminip.php.
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component adminping.php.
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component adminweixin.php.
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component adminnotify.php.
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component adminsmtp.php.
SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/adminping.php file.
A vulnerability was found in SeaCMS 11.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/config.ftp.php of the component Picture Management. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-221630 is the identifier assigned to this vulnerability.
SeaCMS 6.64 allows SQL Injection via the upload/admin/adminvideo.php order parameter.
CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the referenceid parameter.
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to adminmembersgroup.php.
An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admintopicvod.php request.
seacms V11.5 is affected by an arbitrary code execution vulnerability in adminconfig.php.
The component /jqueryfileupload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.