Vulnerabilities (CVE)

Filtered by vendor Discuz Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-5561 1 Discuz 1 Discuz Gbk 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL commands via the cdb_auth cookie.
CVE-2008-6957 1 Discuz 1 Discuz\! 2017-09-29 7.5 HIGH N/A
member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter.
CVE-2009-4621 2 Discuz, Patching 2 Discuz\!, Jianghu Inn 2017-09-19 7.5 HIGH N/A
SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to forummission.php.
CVE-2010-4912 1 Discuz 1 Ucenter Home 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid parameter in a view action.