Exploit Database

148,724 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-2475 GITEE LOW java
Dromara J2eeFAST < 2.6.0 - Cross-Site Scripting via System Message Handler
A vulnerability was found in Dromara J2eeFAST up to 2.6.0 and classified as problematic. This issue affects some unknown processing of the component System Message Handler. The manipulation of the argument 主题 leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 7a9e1a00e3329fdc0ae05f7a8257cce77037134d. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-227867.
by yu199195
2,242 stars
CVSS 3.5
CVE-2023-2476 GITEE LOW java
Dromara J2eeFAST <= 2.6.0 - Cross-Site Scripting in Announcement Handler
A vulnerability was found in Dromara J2eeFAST up to 2.6.0. It has been classified as problematic. Affected is an unknown function of the component Announcement Handler. The manipulation of the argument 系统工具/公告管理 leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 7a9e1a00e3329fdc0ae05f7a8257cce77037134d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-227868.
by yu199195
2,242 stars
CVSS 3.5
CVE-2020-21783 GITEE MEDIUM php
IBOS 4.5.4 - Cross-Site Scripting via Email Body Content Parameter
In IBOS 4.5.4 the email function has a cross site scripting (XSS) vulnerability in emailbody[content] parameter.
by ibos
1,962 stars
CVSS 6.1
CVE-2020-21785 GITEE HIGH php
IBOS 4.5.4 Open - OS Command Injection via Database Backup
In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.
by ibos
1,962 stars
CVSS 8.8
CVE-2020-21786 GITEE CRITICAL php
IBOS 4.5.4 Open - Arbitrary File Inclusion via CronController.php
In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php.
by ibos
1,962 stars
CVSS 9.8
CVE-2023-1278 GITEE LOW php
ibos < 4.5.5 - Cross-Site Scripting via accesstoken Parameter
A vulnerability, which was classified as problematic, has been found in IBOS up to 4.5.5. Affected by this issue is some unknown functionality of the file mobil/index.php. The manipulation of the argument accesstoken leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-222608.
by ibos
1,962 stars
CVSS 3.5
CVE-2023-1111 GITEE LOW java
FastCMS < 0.1.5 - Cross-Site Scripting via New Article Tab Title Parameter
A vulnerability was found in FastCMS up to 0.1.5 and classified as problematic. Affected by this issue is some unknown functionality of the component New Article Tab. The manipulation of the argument Title leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-266126 is the identifier assigned to this vulnerability.
by dianbuapp_admin
1,648 stars
CVSS 2.4
CVE-2019-3576 GITEE CRITICAL java
inxedu < 2018-12-24 - SQL Injection via deleteFaveorite PATH_INFO
inxedu through 2018-12-24 has a SQL Injection vulnerability that can lead to information disclosure via the deleteFaveorite/ PATH_INFO. The vulnerable code location is com.inxedu.os.edu.controller.user.UserController#deleteFavorite (aka deleteFavorite in com/inxedu/os/edu/controller/user/UserController.java), where courseFavoritesService.deleteCourseFavoritesById is mishandled during use of MyBatis. NOTE: UserController.java has a spelling variation in an annotation: a @RequestMapping("/deleteFaveorite/{ids}") line followed by a "public ModelAndView deleteFavorite" line.
by inxeduopen
1,602 stars
CVSS 9.8
CVE-2019-7684 GITEE CRITICAL java
inxedu <2018-12-24 - Code Injection
inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.common.controller.VideoUploadController#gok4 (com/inxedu/os/common/controller/VideoUploadController.java). The attacker uses the /video/uploadvideo fileType parameter to change the list of acceptable extensions from jpg,gif,png,jpeg to jpg,gif,png,jsp,jpeg.
by inxeduopen
1,602 stars
CVSS 9.8
CVE-2020-21152 GITEE CRITICAL java
inxedu 2.0.6 - SQL Injection via saverolefunction functionIds Parameter
SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunction.
by inxeduopen
1,602 stars
CVSS 9.8
CVE-2020-35326 GITEE CRITICAL java
inxedu 2.0.6 - SQL Injection via WebsiteImagesMapper.xml id Parameter
SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0.6 via the id value.
by inxeduopen
1,602 stars
CVSS 9.8
CVE-2020-35430 GITEE CRITICAL java
Inxedu v2.0.6 - SQL Injection via Admin MsgSystemController ids Parameter
SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystem.
by inxeduopen
1,602 stars
CVSS 9.8
CVE-2022-4353 GITEE LOW java
pb-cms 2.0 - Cross-Site Scripting in IpUtil.getIpAddr
A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this vulnerability is the function IpUtil.getIpAddr. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215113 was assigned to this vulnerability.
by LinZhaoguan
1,410 stars
CVSS 3.5
CVE-2022-4354 GITEE MEDIUM java
pb-cms 2.0 - Cross-Site Scripting in Message Board Comment Handler
A vulnerability was found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /blog/comment of the component Message Board. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-215114 is the identifier assigned to this vulnerability.
by LinZhaoguan
1,410 stars
CVSS 4.3
CVE-2024-10477 GITEE LOW java
pb-cms < 2.0.1 - Cross-Site Scripting in Permission Management Page
A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknown code of the file /admin#permissions of the component Permission Management Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
by LinZhaoguan
1,410 stars
CVSS 2.4
CVE-2024-10478 GITEE LOW java
pb-cms < 2.0.1 - Cross-Site Scripting in Edit Article Handler
A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms up to 2.0.1. This issue affects some unknown processing of the file /admin#article/edit?id=2 of the component Edit Article Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
by LinZhaoguan
1,410 stars
CVSS 2.4
CVE-2024-10479 GITEE LOW java
pb-cms < 2.0.1 - Cross-Site Scripting in Theme Management Module
A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
by LinZhaoguan
1,410 stars
CVSS 2.4
CVE-2023-2862 GITEE LOW c#
SiteServer CMS < 7.2.1 - Cross-Site Scripting via ajaxDivId Parameter
A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-229818 is the identifier assigned to this vulnerability.
by siteserver
1,291 stars
CVSS 3.5
CVE-2022-27960 GITEE MEDIUM java
ofcms 1.1.4 - Arbitrary User Information Modification via SysUserController.java user_id Parameter
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information.
by oufu
1,025 stars
CVSS 5.4
CVE-2022-27961 GITEE MEDIUM java
OFCMS 1.1.4 - Stored Cross-Site Scripting via Company Comment Text Box
A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment text box.
by oufu
1,025 stars
CVSS 5.4
CVE-2022-29653 GITEE MEDIUM java
OFCMS v1.1.4 - Cross-Site Scripting via /admin/comn/service/update.json
OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.
by oufu
1,025 stars
CVSS 6.1
CVE-2023-24760 GITEE HIGH java
Ofcms <1.1.4 - Privilege Escalation
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.
by oufu
1,025 stars
CVSS 8.8
CVE-2023-24760 GITEE HIGH java
Ofcms <1.1.4 - Privilege Escalation
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.
by oufu
1,025 stars
CVSS 8.8
CVE-2023-51807 GITEE MEDIUM java
ofcms 1.14 - Cross-Site Scripting via Title Addition Component
Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component.
by oufu
1,025 stars
CVSS 5.4
CVE-2023-3058 GITEE LOW php
07FLY CRM < 1.2.0 - Cross-Site Scripting in User Profile Handler
A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unknown code of the component User Profile Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230560.
by 07fly
958 stars
CVSS 3.5