A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=delpl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.
A vulnerability was found in SeaCMS up to 13.3. The impacted element is an unknown function of the file adminvideo.php. Performing a manipulation of the argument eid results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.
A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is some unknown functionality of the file /admintype.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component adminfiles.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component adminip.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admintemplate.php.
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the filegetcontents function at adminsafefile.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at adminweixin.php.
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the filegetcontents function at adminsafe.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component adminsmtp.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component adminping.php.
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component adminnotify.php.
Seacms <=13.3 is vulnerable to SQL Injection in admincollectnews.php.
Seacms <13.3 is vulnerable to SQL Injection in adminpay.php.
Seacms <=13.3 is vulnerable to SQL Injection in admintypenews.php.
Seacms <=13.3 is vulnerable to SQL Injection in adminpaylog.php.
Seacms <=13.3 is vulnerable to SQL Injection in admincollect.php that allows an authenticated attacker to exploit the database.
Seacms <=13.3 is vulnerable to SQL Injection in adminzyk.php.
Seacms <=13.3 is vulnerable to SQL Injection in adminreslib.php.
Seacms <=13.3 is vulnerable to SQL Injection in adminmembers.php.
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.
SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in adminnotify.php.
Vulnerability in adminip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.