← Back

Dimofinf

dimofinf

4 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Dawaween
dawaween
Dimofinf Cms
dimofinf_cms

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dimofinf
1Dimofinf Cms
Nov 21, 2024
Jun 11, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
1Dimofinf
1Dawaween
Apr 23, 2026
Sep 23, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter in a sec list action, a different vector than CVE-2006-1018.
1Dimofinf
1Infinity Script
Apr 23, 2026
Sep 16, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username field.
1Dimofinf
1Infinity Script
Apr 23, 2026
Sep 16, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the options[style_dir] parameter to the de...Show more
Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the options[style_dir] parameter to the default URI.Show less