Skip to main content

Vendor/product archive

doorgets / doorgets_cms CVEs

Beta · best-effort

22 CVEs tagged to doorgets / doorgets_cms2 Critical, 10 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2019-11626

Published Apr 30, 2019

routers/ajaxRouter.php in doorGets 7.0 has a web site physical path leakage vulnerability, as demonstrated by an ajax/index.php?uri=1234%5c request.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11625

Published Apr 30, 2019

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/emailingRequest.php. A remote background administrator privilege user (or a user with permission to m…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11624

Published Apr 30, 2019

doorGets 7.0 has an arbitrary file deletion vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote background administrator privilege user can exploit thi…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11623

Published Apr 30, 2019

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=siteweb. A remote background administrator privilege user (or a…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11622

Published Apr 30, 2019

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permissio…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11621

Published Apr 30, 2019

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=network. A remote background administrator privilege user (or a…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11620

Published Apr 30, 2019

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permissio…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11619

Published Apr 30, 2019

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=analytics. A remote background administrator privilege user (or…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11618

Published Apr 30, 2019

doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this vulnerability to gain administrator privileges for the creation and modification…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11617

Published Apr 30, 2019

doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "Google Analytics code" modific…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11616

Published Apr 30, 2019

doorGets 7.0 has a sensitive information disclosure vulnerability in /setup/temp/admin.php and /setup/temp/database.php. A remote unauthenticated attacker could exploit this vulne…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11615

Published Apr 30, 2019

/fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can use this vulnerability to upload backdoor files to control…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11614

Published Apr 30, 2019

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/commentView.php. A remote unauthorized attacker could exploit the vulnerability to obtain database sensi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11613

Published Apr 30, 2019

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/contactView.php. A remote normal registered user could exploit the vulnerability to obtain database sens…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11612

Published Apr 30, 2019

doorGets 7.0 has an arbitrary file deletion vulnerability in /fileman/php/deletefile.php. A remote unauthenticated attacker can exploit this vulnerability to delete arbitrary file…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11611

Published Apr 30, 2019

doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/download.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11610

Published Apr 30, 2019

doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/downloaddir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain serve…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11609

Published Apr 30, 2019

doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/movefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-s…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11608

Published Apr 30, 2019

doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/renamefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11607

Published Apr 30, 2019

doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copydir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-se…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11606

Published Apr 30, 2019

doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1459

Published Feb 11, 2014

SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the _position_do…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1