Mochazz

2 exploits Active since Oct 2018
CVE-2018-18083 WRITEUP CRITICAL WRITEUP
Comsenz Duomicms - Code Injection
An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.
CVSS 9.8
CVE-2018-18084 WRITEUP CRITICAL WRITEUP
Comsenz Duomicms - SQL Injection
An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.
CVSS 9.8