Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown
CVE-2021-36426
Disclosure Date: February 03, 2023 (last updated February 24, 2025)
File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to include/inc_lib/general.inc.php.
0
Attacker Value
Unknown
CVE-2021-36425
Disclosure Date: February 03, 2023 (last updated February 24, 2025)
Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $file parameter to unlink method in include/inc_act/act_ftptakeover.php file.
0
Attacker Value
Unknown
CVE-2021-36424
Disclosure Date: February 03, 2023 (last updated February 24, 2025)
An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.
0
Attacker Value
Unknown
CVE-2021-4301
Disclosure Date: January 07, 2023 (last updated February 24, 2025)
A vulnerability was found in slackero phpwcms up to 1.9.26 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument $phpwcms['db_prepend'] leads to sql injection. The attack may be launched remotely. Upgrading to version 1.9.27 is able to address this issue. The patch is identified as 77dafb6a8cc1015f0777daeb5792f43beef77a9d. It is recommended to upgrade the affected component. VDB-217418 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2021-4302
Disclosure Date: January 04, 2023 (last updated February 24, 2025)
A vulnerability was found in slackero phpwcms up to 1.9.26. It has been classified as problematic. This affects an unknown part of the component SVG File Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.9.27 is able to address this issue. The patch is named b39db9c7ad3800f319195ff0e26a0981395b1c54. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217419.
0
Attacker Value
Unknown
CVE-2020-19855
Disclosure Date: September 08, 2021 (last updated February 23, 2025)
phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.
0
Attacker Value
Unknown
CVE-2020-21784
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
0
Attacker Value
Unknown
CVE-2018-12990
Disclosure Date: June 30, 2018 (last updated November 26, 2024)
phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.
0
Attacker Value
Unknown
CVE-2017-15872
Disclosure Date: October 24, 2017 (last updated November 26, 2024)
phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.
0
Attacker Value
Unknown
CVE-2011-3789
Disclosure Date: September 24, 2011 (last updated October 04, 2023)
phpwcms 1.4.7 r412 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by template/inc_script/frontend_render/disabled/majonavi.php and certain other files.
0