Show filters
32 Total Results
Displaying 11-20 of 32
Sort by:
Attacker Value
Unknown

CVE-2023-29597

Disclosure Date: April 13, 2023 (last updated December 23, 2023)
bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.
Attacker Value
Unknown

CVE-2023-27812

Disclosure Date: April 13, 2023 (last updated December 23, 2023)
bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.
Attacker Value
Unknown

CVE-2023-23151

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php.
Attacker Value
Unknown

CVE-2022-28528

Disclosure Date: April 26, 2022 (last updated February 23, 2025)
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.
Attacker Value
Unknown

CVE-2021-44610

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php.
Attacker Value
Unknown

CVE-2021-44608

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php.
Attacker Value
Unknown

CVE-2020-35761

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.
Attacker Value
Unknown

CVE-2020-35762

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.
Attacker Value
Unknown

CVE-2020-35760

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).
Attacker Value
Unknown

CVE-2020-35759

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).