Skip to content

Instantly share code, notes, and snippets.

@ChubbyZ
ChubbyZ / CVE-2023-42321
Last active September 20, 2023 06:18
CVE-2023-42321
[CVE-ID]
CVE-2023-42321
[CNVD-ID]
CNVD-2023-68150
[Description]
In the iCMS V7.0.16 version, the session in the session is hijacked, and members, roles and administrator accounts can be added arbitrarily without logging in to the account.
------------------------------------------
@ChubbyZ
ChubbyZ / CVE-2023-42322
Last active September 20, 2023 06:19
CVE-2023-42322
[CVE-ID]
CVE-2023-42322
[CNVD-ID]
CNVD-2023-66769
[Description]
In the icms V7.0.16 version, the attacker obtains the session through some means and can hijack the session of the website. You can perform operations on the website backend without logging in, such as deleting any files, comments, users, etc.
------------------------------------------
@ChubbyZ
ChubbyZ / CVE-2023-40953
Created September 6, 2023 02:36
CVE-2023-40953
[CVE-ID]
CVE-2023-40953
------------------------------------------
[Description]
icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).
@ChubbyZ
ChubbyZ / CVE-2023-39805
Created August 9, 2023 04:29
CVE-2023-39805
[CVE-ID]
CVE-2023-39805
------------------------------------------
[Description]
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability
via the where parameter at admincp.php.
------------------------------------------
@ChubbyZ
ChubbyZ / CVE-2023-39806
Last active August 10, 2023 01:41
CVE-2023-39806
[CVE-ID]
CVE-2023-39806
------------------------------------------
[Description]
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability
via the bakupdata function.
------------------------------------------