Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2019-10766

Disclosure Date: November 19, 2019 (last updated November 27, 2024)
Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.
Attacker Value
Unknown

CVE-2017-12905

Disclosure Date: September 25, 2017 (last updated November 26, 2024)
Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrary code via the url parameter to Launderer.php.
Attacker Value
Unknown

CVE-2017-7402

Disclosure Date: April 03, 2017 (last updated November 26, 2024)
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.
0
Attacker Value
Unknown

CVE-2017-7361

Disclosure Date: March 31, 2017 (last updated November 26, 2024)
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.
0
Attacker Value
Unknown

CVE-2017-7360

Disclosure Date: March 31, 2017 (last updated November 26, 2024)
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.
0
Attacker Value
Unknown

CVE-2017-7359

Disclosure Date: March 31, 2017 (last updated November 26, 2024)
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.
0
Attacker Value
Unknown

CVE-2017-7362

Disclosure Date: March 31, 2017 (last updated November 26, 2024)
Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.
0
Attacker Value
Unknown

CVE-2017-7363

Disclosure Date: March 31, 2017 (last updated November 26, 2024)
Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack.
0
Attacker Value
Unknown

CVE-2014-3786

Disclosure Date: June 04, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitrary web script or HTML via the (1) uemail or (2) subject parameter in the Contact form to contact/.
0
Attacker Value
Unknown

CVE-2011-4710

Disclosure Date: December 08, 2011 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI.
0