← Back

Doorgets

doorgets

Vendor: Doorgets • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Doorgets
1Doorgets
Nov 21, 2024
Dec 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
doorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a dg-user/?controller=theme&action=edit&name=doorgets&file=../../1.txt%00 URI with content in the theme_content...Show more
doorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a dg-user/?controller=theme&action=edit&name=doorgets&file=../../1.txt%00 URI with content in the theme_content_nofi parameter.Show less
1Doorgets
1Doorgets
Nov 21, 2024
May 15, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
dg-user/?controller=users&action=add in doorGets 7.0 has CSRF that results in adding an administrator account.