Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2019-6244

Disclosure Date: January 12, 2019 (last updated November 27, 2024)
An issue was discovered in UsualToolCMS 8.0. cmsadmin/a_sqlbackx.php?t=sql allows CSRF attacks that can execute SQL statements, and consequently execute arbitrary PHP code by writing that code into a .php file.
0
Attacker Value
Unknown

CVE-2018-20128

Disclosure Date: December 13, 2018 (last updated November 27, 2024)
An issue was discovered in UsualToolCMS v8.0. cmsadmin\a_sqlback.php allows remote attackers to delete arbitrary files via a backname[] directory-traversal pathname followed by a crafted substring.
0
Attacker Value
Unknown

CVE-2018-18422

Disclosure Date: October 17, 2018 (last updated November 27, 2024)
UsualToolCMS 8.0 allows CSRF for adding a user account via the cmsadmin/a_adminx.php?x=a URI.
0
Attacker Value
Unknown

CVE-2018-16435

Disclosure Date: September 04, 2018 (last updated November 27, 2024)
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.
0
Attacker Value
Unknown

CVE-2017-17733

Disclosure Date: December 18, 2017 (last updated November 26, 2024)
Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.
0
Attacker Value
Unknown

CVE-2016-10165

Disclosure Date: February 03, 2017 (last updated December 21, 2023)
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
Attacker Value
Unknown

CVE-2011-4551

Disclosure Date: October 01, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.
0
Attacker Value
Unknown

CVE-2012-3996

Disclosure Date: July 12, 2012 (last updated October 04, 2023)
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.
0
Attacker Value
Unknown

CVE-2009-0792

Disclosure Date: April 14, 2009 (last updated November 08, 2023)
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
0
Attacker Value
Unknown

CVE-2009-0583

Disclosure Date: March 23, 2009 (last updated October 04, 2023)
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
0