Filtered by vendor Comsenz Subscriptions
Filtered by product Duomicms Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-18084 1 Comsenz 1 Duomicms 2020-06-17 9.8 Critical
An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.
CVE-2018-18083 1 Comsenz 1 Duomicms 2018-11-29 N/A
An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.