« Volver al listado

ACC

ACC DM Corporative CMS: vulnerabilidades y CVE

ACC DM Corporative CMS tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses0
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-40662Media (6.9)0.35%—10 jun 2025
Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents of webroot/file, if navigating to a non-existent file.
CVE-2025-40661Media (6.9)0.33%—10 jun 2025
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in…
CVE-2025-40660Media (6.9)0.33%—10 jun 2025
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in…
CVE-2025-40659Media (6.9)0.33%—10 jun 2025
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in…
CVE-2025-40658Media (6.9)0.33%—10 jun 2025
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in…
CVE-2025-40657Crítica (9.3)0.37%—10 jun 2025
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the codform parameter in /modules/forms/collectform.asp.
CVE-2025-40656Crítica (9.3)0.37%—10 jun 2025
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the cod parameter in /administer/node-selection/data.asp.
CVE-2025-40655Crítica (9.3)0.37%—10 jun 2025
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name parameter in /antcatalogue.asp.
CVE-2025-40654Crítica (9.3)0.37%—10 jun 2025
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name and cod parameters in /antbuspre.asp.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System4
  2. T1190 Exploit Public-Facing Application4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de ACC