Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2019-9549

Disclosure Date: March 03, 2019 (last updated November 27, 2024)
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstrated by adding a level=1 account, a similar issue to CVE-2018-18935.
0
Attacker Value
Unknown

CVE-2018-18935

Disclosure Date: November 05, 2018 (last updated November 27, 2024)
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account.
0
Attacker Value
Unknown

CVE-2018-18934

Disclosure Date: November 05, 2018 (last updated November 27, 2024)
An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a ZIP file containing arbitrary PHP code (that is extracted and can be executed). This can also be exploited via CSRF.
0
Attacker Value
Unknown

CVE-2018-18936

Disclosure Date: November 05, 2018 (last updated November 27, 2024)
An issue was discovered in PopojiCMS v2.0.1. admin_library.php allows remote attackers to delete arbitrary files via directory traversal in the po-admin/route.php?mod=library&act=delete id parameter.
0