VYPR
Vendor

Howchen

Products
2
CVEs
3
Across products
3
Status
Private

Products

2

Recent CVEs

3
  • CVE-2018-16239CriAug 30, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.

  • CVE-2018-16238HigAug 30, 2018
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to the admin.php?s=/Tpl/Update.html URI. For example, this can update the Web/Tpl/default/head.html file.

  • CVE-2018-16237LowAug 30, 2018
    risk 0.18cvss 2.7epss 0.01

    An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI.