Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2023-6772 A vulnerability, which was classified as critical, was found in OTCMS 7.01. Affected is an unknown function of the file /admin/ind_backstage.php. The… Otcms No fix yet Fix from $1,9502023-12-13 CRITICAL 9.8 CVE-2023-1797 A vulnerability classified as critical was found in OTCMS 6.0.1. Affected by this vulnerability is an unknown functionality of the file sysCheckFile.… Otcms No fix yet Fix from $2,3002023-04-02 CRITICAL 9.8 CVE-2023-1634 A vulnerability was found in OTCMS 6.72. It has been classified as critical. Affected is the function UseCurl of the file /admin/info_deal.php of the… Otcms No fix yet Fix from $2,3002023-03-25 MEDIUM 6.1 CVE-2023-1635 A vulnerability was found in OTCMS 6.72. It has been declared as problematic. Affected by this vulnerability is the function AutoRun of the file apiR… Otcms No fix yet Fix from $1,6002023-03-25 HIGH 7.2 CVE-2019-17370 OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block t… Otcms No fix yet Fix from $1,9502019-10-09 MEDIUM 6.5 CVE-2019-17369 OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superad… Otcms No fix yet Fix from $1,6002019-10-09 MEDIUM 6.1 CVE-2019-13971 OTCMS 3.81 allows XSS via the mode parameter in an apiRun.php?mudi=autoRun request. Otcms No fix yet Fix from $1,6002019-07-19 HIGH 8.1 CVE-2018-17364 OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter. Otcms No fix yet Fix from $1,9502018-09-23 MEDIUM 6.1 CVE-2018-17085 An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr. Otcms No fix yet Fix from $1,6002018-09-16 MEDIUM 6.1 CVE-2018-17086 An issue was discovered in OTCMS 3.61. XSS exists in admin/share_switch.php via these parameters: fieldName fieldName2 tabName. Otcms No fix yet Fix from $1,6002018-09-16 MEDIUM 6.1 CVE-2018-8973 OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request. Otcms No fix yet Fix from $1,6002018-03-24