Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2019-9611

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter, to write arbitrary content (in the file_content parameter) into an arbitrary file (specified by the file_name parameter). This is related to the save function in TemplateController.java.
0
Attacker Value
Unknown

CVE-2019-9615

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java.
0
Attacker Value
Unknown

CVE-2019-9616

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI.
0
Attacker Value
Unknown

CVE-2019-9617

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadFile URI.
0
Attacker Value
Unknown

CVE-2019-9612

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/upload URI.
0
Attacker Value
Unknown

CVE-2019-9609

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/editUploadImage URI.
0
Attacker Value
Unknown

CVE-2019-9613

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadVideo URI.
0