RSS   Vulnerabilities for 'Wuzhicms'   RSS

2021-04-02
 
CVE-2020-21590

CWE-22
 

 
Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbitrary directories via the dir parameter.

 
2019-02-24
 
CVE-2019-9108

CWE-79
 

 
XSS exists in WUZHI CMS 4.1.0 via index.php?m=core&f=map&v=baidumap&x=[XSS]&y=[XSS] to coreframe/app/core/map.php.

 
2018-12-28
 
CVE-2018-20572

CWE-89
 

 
WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.

 
2018-07-20
 
CVE-2018-14472

CWE-89
 

 
An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly into execution without any filtering, leading to SQL injection.

 
2018-06-05
 
CVE-2018-11722

CWE-89
 

 
WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.

 
2018-04-19
 
CVE-2018-10221

CWE-79
 

 
An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parameter to the index.php?m=tags&f=index&v=add&&_su=wuzhicms URI. After a website editor (whose privilege is lower than the administrator) logs in, he can add a new TAGS with the XSS payload.

 
2018-04-10
 
CVE-2018-9927

CWE-352
 

 
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=member&f=index&v=add.

 
 
CVE-2018-9926

CWE-352
 

 
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add.

 

 >>> Vendor: Wuzhicms 2 Products
Wuzhicms
Wuzhi cms


Copyright 2021, cxsecurity.com

 

Back to Top