Dedecmsv6
by Dedebiz
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44120 | Cri | 0.64 | 9.8 | 0.01 | Nov 23, 2022 | dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php. | ||
| CVE-2022-44118 | Cri | 0.64 | 9.8 | 0.02 | Nov 23, 2022 | dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php. | ||
| CVE-2022-43196 | Cri | 0.59 | 9.1 | 0.01 | Nov 23, 2022 | dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php. | ||
| CVE-2022-36215 | Hig | 0.47 | 7.2 | 0.02 | Aug 17, 2022 | DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php. |
- risk 0.64cvss 9.8epss 0.01
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.
- risk 0.64cvss 9.8epss 0.02
dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.
- risk 0.59cvss 9.1epss 0.01
dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.
- risk 0.47cvss 7.2epss 0.02
DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php.