Known Vulnerabilities for products from Damicms
Listed below are 11 of the newest known vulnerabilities associated with the vendor "Damicms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-21236 json | A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate... | 8.8 - HIGH | 2021-12-27 | 2022-01-10 |
| CVE-2020-18458 json | Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin... | 8 - HIGH | 2021-08-12 | 2021-08-17 |
| CVE-2020-18451 json | Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in LabelActio... | 4.8 - MEDIUM | 2021-08-12 | 2021-08-13 |
| CVE-2018-20571 json | DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstrated b... | 7.5 - HIGH | 2018-12-28 | 2019-01-11 |
| CVE-2018-16331 json | admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password. | 8.8 - HIGH | 2018-09-02 | 2018-10-23 |
| CVE-2018-16239 json | An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to deter... | 9.8 - CRITICAL | 2018-08-30 | 2019-10-03 |
| CVE-2018-16238 json | An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to the ... | 7.2 - HIGH | 2018-08-30 | 2018-10-19 |
| CVE-2018-16237 json | An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, a... | 2.7 - LOW | 2018-08-30 | 2018-10-19 |
| CVE-2018-15844 json | An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password... | 8.8 - HIGH | 2018-08-25 | 2018-10-17 |
| CVE-2018-14831 json | An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in the se... | 4.9 - MEDIUM | 2019-07-10 | 2019-07-17 |
| CVE-2018-13031 json | DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account. | 8.8 - HIGH | 2018-07-05 | 2021-06-17 |
Known software with vulnerabilities from Damicms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Damicms | Damicms | 6.0.0 |