Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Letmejustdoit

#15668of 53,635
17.3Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2018-15441
7.5
2018-12-28
Damicms · Damicms · CVE-2018-20571
**Name of the Vulnerable Software and Affected Versions** DamiCMS version 6.0.1 **Description** The issue allows remote attackers to read arbitrary files by sending a crafted request to the `admin.php?s=Tpl/Add/id` endpoint. For example, an attacker can read the global configuration file by accessing `admin.php?s=Tpl/Add/id/.PublicConfigconfig.ini.php`. **Recommendations** For DamiCMS version 6.0.1, restrict access to the `admin.php?s=Tpl/Add/id` endpoint to minimize the risk of exploitation. Avoid using the `id` parameter in the affected endpoint until the issue is resolved.
PT-2018-15442
9.8
2018-12-28
Wuzhi · Wuzhi Cms · CVE-2018-20572
**Name of the Vulnerable Software and Affected Versions** WUZHI CMS version 4.1.0 **Description** The issue allows SQL injection via the `keywords` parameter in the "index.php?m=promote&f=index&v=search" endpoint. **Recommendations** For WUZHI CMS version 4.1.0, avoid using the `keywords` parameter in the affected endpoint until the issue is resolved.