Sdcms
Sdcms · 6 CVEs
The theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commands
Nov 8, 2024
There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filena…
Mar 11, 2019
An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function'…
Mar 11, 2019
app/plug/attachment/controller/admincontroller.php in SDCMS 1.6 allows reading arbitrary files via a /?m=plug&c=admin&a…
Nov 29, 2018
An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function i…
Nov 25, 2018
An issue was discovered in SDcms v1.5. Cross-site request forgery (CSRF) vulnerability in /WWW//app/admin/controller/ad…
May 12, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-50809 | The theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commands | HIGH | 0.72% | Nov 8, 2024 |
| CVE-2019-9652 | There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and providing… | HIGH | 0.61% | Mar 11, 2019 |
| CVE-2019-9651 | An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's filtering is not strict, resulting in… | CRITICAL | 2.56% | Mar 11, 2019 |
| CVE-2018-19748 | app/plug/attachment/controller/admincontroller.php in SDCMS 1.6 allows reading arbitrary files via a /?m=plug&c=admin&a=index&p=attachment&root= directory trav… | HIGH | 2.02% | Nov 29, 2018 |
| CVE-2018-19520 | An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in an attempt to block certain PHP functi… | HIGH | 2.92% | Nov 25, 2018 |
| CVE-2018-11004 | An issue was discovered in SDcms v1.5. Cross-site request forgery (CSRF) vulnerability in /WWW//app/admin/controller/admincontroller.php allows remote attacker… | HIGH | 0.57% | May 12, 2018 |
Showing 1 to 6 of 6 CVEs