Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
Unknown

CVE-2024-12901

Disclosure Date: December 23, 2024 (last updated January 05, 2025)
A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of the component API Endpoint. The manipulation of the argument password leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown

CVE-2024-12900

Disclosure Date: December 23, 2024 (last updated January 05, 2025)
A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /install/installdb.php of the component Configuration File Handler. The manipulation of the argument database password leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown

CVE-2020-36082

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.
Attacker Value
Unknown

CVE-2023-34756

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.
Attacker Value
Unknown

CVE-2023-34755

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.
Attacker Value
Unknown

CVE-2023-34754

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.
Attacker Value
Unknown

CVE-2023-34753

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.
Attacker Value
Unknown

CVE-2023-34752

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.
Attacker Value
Unknown

CVE-2023-34751

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.
Attacker Value
Unknown

CVE-2023-34750

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.