Show filters
34 Total Results
Displaying 11-20 of 34
Sort by:
Attacker Value
Unknown
CVE-2018-17418
Disclosure Date: March 07, 2019 (last updated November 27, 2024)
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the forbidden_types variable.
0
Attacker Value
Unknown
CVE-2018-18694
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
admin/index.php?id=filesmanager in Monstra CMS 3.0.4 allows remote authenticated administrators to trigger stored XSS via JavaScript content in a file whose name lacks an extension. Such a file is interpreted as text/html in certain cases.
0
Attacker Value
Unknown
CVE-2018-16819
Disclosure Date: September 18, 2018 (last updated November 27, 2024)
admin/index.php in Monstra CMS 3.0.4 allows arbitrary file deletion via id=filesmanager&path=uploads/.......//./.......//./&delete_file= requests.
0
Attacker Value
Unknown
CVE-2018-16820
Disclosure Date: September 18, 2018 (last updated November 27, 2024)
admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.
0
Attacker Value
Unknown
CVE-2018-17024
Disclosure Date: September 13, 2018 (last updated November 27, 2024)
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action.
0
Attacker Value
Unknown
CVE-2018-17025
Disclosure Date: September 13, 2018 (last updated November 27, 2024)
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role.
0
Attacker Value
Unknown
CVE-2018-17026
Disclosure Date: September 13, 2018 (last updated November 27, 2024)
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page&name=error404 action, a different vulnerability than CVE-2018-10121.
0
Attacker Value
Unknown
CVE-2018-16977
Disclosure Date: September 12, 2018 (last updated November 27, 2024)
Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, DOCUMENT_ROOT, and SERVER_ADMIN) in libraries/Gelato/ErrorHandler/Resources/Views/Errors/exception.php.
0
Attacker Value
Unknown
CVE-2018-16978
Disclosure Date: September 12, 2018 (last updated November 27, 2024)
Monstra CMS V3.0.4 has XSS when ones tries to register an account with a crafted password parameter to users/registration, a different vulnerability than CVE-2018-11473.
0
Attacker Value
Unknown
CVE-2018-16979
Disclosure Date: September 12, 2018 (last updated November 27, 2024)
Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-2943.
0