Vulnerabilities > Douco > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-01-13 | CVE-2022-46438 | Cross-site Scripting vulnerability in Douco Douphp 1.720221118 A cross-site scripting (XSS) vulnerability in the /admin/article_category.php component of DouPHP v1.7 20221118 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the description parameter. | 5.4 |
2022-03-30 | CVE-2022-24131 | Cross-site Scripting vulnerability in Douco Douphp 1.6 DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which will lead to JavaScript code execution. | 4.3 |
2022-03-25 | CVE-2022-25574 | Cross-site Scripting vulnerability in Douco Douphp 1.6 A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file. | 4.8 |
2021-12-08 | CVE-2021-3370 | Cross-site Scripting vulnerability in Douco Douphp 1.6 DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php. | 4.3 |
2019-06-03 | CVE-2019-12564 | Improper Authentication vulnerability in Douco Douphp 1.5 In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/DyyyymmddThhmmss.sql filenames. | 5.0 |
2018-12-28 | CVE-2018-20567 | Incorrect Permission Assignment for Critical Resource vulnerability in Douco Douphp 1.5 An issue was discovered in DouCo DouPHP 1.5 20181221. | 5.0 |
2018-12-28 | CVE-2018-20566 | Path Traversal vulnerability in Douco Douphp 1.5 An issue was discovered in DouCo DouPHP 1.5 20181221. | 5.0 |
2018-12-24 | CVE-2018-20419 | Cross-Site Request Forgery (CSRF) vulnerability in Douco Douphp 1.5 DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account. | 6.8 |