Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2019-5956

Disclosure Date: September 12, 2019 (last updated November 27, 2024)
Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors.
Attacker Value
Unknown

CVE-2018-14387

Disclosure Date: July 18, 2018 (last updated November 27, 2024)
An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authenticate against the server using the same session identifier. The attacker can access the user's account through the active session. The Session Fixation attack fixes a session on the victim's browser, so the attack starts before the user logs in.
0
Attacker Value
Unknown

CVE-2018-7172

Disclosure Date: February 27, 2018 (last updated November 26, 2024)
In index.php in WonderCMS before 2.4.1, remote attackers can delete arbitrary files via directory traversal.
0
Attacker Value
Unknown

CVE-2018-1000062

Disclosure Date: February 09, 2018 (last updated November 26, 2024)
WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction(), 'svg' => 'image/svg+xml' that can result in An attacker can execute arbitrary script on an unsuspecting user's browser. This attack appear to be exploitable via Crafted SVG File.
0
Attacker Value
Unknown

CVE-2017-14523

Disclosure Date: January 26, 2018 (last updated November 08, 2023)
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack
0
Attacker Value
Unknown

CVE-2017-14522

Disclosure Date: January 26, 2018 (last updated November 08, 2023)
In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOTE: the vendor disputes this issue stating that this is a feature that enables only a logged in administrator to write execute JavaScript anywhere on their website
0
Attacker Value
Unknown

CVE-2017-14521

Disclosure Date: January 26, 2018 (last updated November 26, 2024)
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
0
Attacker Value
Unknown

CVE-2017-7951

Disclosure Date: April 21, 2017 (last updated November 26, 2024)
WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.
0
Attacker Value
Unknown

CVE-2014-8703

Disclosure Date: March 17, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown

CVE-2014-8701

Disclosure Date: March 17, 2017 (last updated November 26, 2024)
Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed password.
0