Vulnerabilities
Vulnerable Software
Ucms Project:  >> Ucms  >> 1.4.7  Security Vulnerabilities
A vulnerability was found in UCMS 1.4.7. It has been classified as problematic. Affected is an unknown function of the file ajax.php?do=strarraylist. The manipulation of the argument strdefault leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239856.
CVSS Score
3.5
EPSS Score
0.001
Published
2023-09-17
A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields.
CVSS Score
5.4
EPSS Score
0.003
Published
2021-09-29
sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter.
CVSS Score
8.8
EPSS Score
0.003
Published
2019-05-21
UCMS 1.4.7 has XSS via the dir parameter in an index.php sadmin_fileedit action.
CVSS Score
4.8
EPSS Score
0.002
Published
2018-12-30
UCMS 1.4.7 has ?do=user_addpost CSRF.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-12-30
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
CVSS Score
8.8
EPSS Score
0.009
Published
2018-12-30
sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-12-30
UCMS 1.4.7 has XSS via the description parameter in an index.php list_editpost action.
CVSS Score
4.8
EPSS Score
0.002
Published
2018-12-30
UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.
CVSS Score
8.8
EPSS Score
0.003
Published
2018-11-22


Contact Us

Shodan ® - All rights reserved