Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Damicms HIGH 8.8
CVE-2020-21236

A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtai…

No fix yet
Fix from $1,950 2021-12-27
Damicms HIGH 8.0
CVE-2020-18458

Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd.

No fix yet
Fix from $1,950 2021-08-12
Damicms HIGH 7.5
CVE-2018-20571

DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstrated by admin.php?s=Tpl/Add/id…

Mitigation only
Fix from $1,950 2018-12-28
Damicms HIGH 8.8
CVE-2018-16331

admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password.

No fix yet
Fix from $1,950 2018-09-02
Damicms CRITICAL 9.8
CVE-2018-16239

An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an e…

No fix yet
Fix from $2,300 2018-08-30
Damicms HIGH 7.2
CVE-2018-16238

An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to the admin.php?s=/Tpl/Update.…

No fix yet
Fix from $1,950 2018-08-30
Damicms HIGH 8.8
CVE-2018-15844

An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin…

No fix yet
Fix from $1,950 2018-08-25
Damicms HIGH 8.8
CVE-2018-13031

DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account.

No fix yet
Fix from $1,950 2018-07-05