Description
A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11353 | A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter. |
References
History
Tue, 22 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geeeeeeeek
Geeeeeeeek dingfanzu |
|
| CPEs | cpe:2.3:a:geeeeeeeek:dingfanzu:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Geeeeeeeek
Geeeeeeeek dingfanzu |
Wed, 16 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Tue, 15 Apr 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-16T14:22:36.193Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28100
Updated: 2025-04-16T14:22:12.334Z
Status : Analyzed
Published: 2025-04-15T18:15:51.057
Modified: 2025-04-22T17:54:47.210
Link: CVE-2025-28100
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD