Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2019-9611
Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter, to write arbitrary content (in the file_content parameter) into an arbitrary file (specified by the file_name parameter). This is related to the save function in TemplateController.java.
0
Attacker Value
Unknown
CVE-2019-9615
Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java.
0
Attacker Value
Unknown
CVE-2019-9616
Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI.
0
Attacker Value
Unknown
CVE-2019-9617
Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadFile URI.
0
Attacker Value
Unknown
CVE-2019-9612
Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/upload URI.
0
Attacker Value
Unknown
CVE-2019-9609
Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/editUploadImage URI.
0
Attacker Value
Unknown
CVE-2019-9613
Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadVideo URI.
0