Lucene search

K

Dsmall Project Security Vulnerabilities

cve
cve

CVE-2018-8906

dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/2.html.

6.1CVSS

5.8AI Score

0.001EPSS

2018-03-22 04:29 AM
16
cve
cve

CVE-2018-9014

dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request.

7.5CVSS

7.3AI Score

0.002EPSS

2018-03-25 06:29 PM
17
cve
cve

CVE-2018-9015

dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box).

5.4CVSS

5.2AI Score

0.001EPSS

2018-03-25 06:29 PM
21
cve
cve

CVE-2018-9016

dsmall v20180320 allows XSS via the main page search box at the public/index.php/home URI.

6.1CVSS

6AI Score

0.001EPSS

2018-03-25 06:29 PM
19
cve
cve

CVE-2018-9017

dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI.

5.4CVSS

5.2AI Score

0.001EPSS

2018-03-25 06:29 PM
26
cve
cve

CVE-2018-9307

dsmall v20180320 allows XSS via the pdr_sn parameter to public/index.php/home/predeposit/index.html.

6.1CVSS

5.9AI Score

0.001EPSS

2022-10-03 04:21 PM
16