Show filters
142 Total Results
Displaying 121-130 of 142
Sort by:
Attacker Value
Unknown

CVE-2016-4895

Disclosure Date: April 12, 2017 (last updated November 26, 2024)
SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-4891

Disclosure Date: April 12, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authentication of an administrator to change settings via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-4896

Disclosure Date: April 12, 2017 (last updated November 26, 2024)
SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthorized information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-4893

Disclosure Date: April 12, 2017 (last updated November 26, 2024)
SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-10165

Disclosure Date: February 03, 2017 (last updated December 21, 2023)
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
Attacker Value
Unknown

CVE-2013-7361

Disclosure Date: April 10, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in SAP CMS and CM Services allows attackers to upload arbitrary files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-5116

Disclosure Date: August 23, 2012 (last updated October 04, 2023)
SQL injection vulnerability in setseed-hub in SetSeed CMS 5.8.20, 5.11.2, and earlier allows remote attackers to execute arbitrary SQL commands via the loggedInUser cookie.
0
Attacker Value
Unknown

CVE-2011-4709

Disclosure Date: December 08, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Hotaru.php in the Search plugin 1.3 for Hotaru CMS allow remote attackers to inject arbitrary web script or HTML via the (1) SITE_NAME parameter to admin_index.php, or the (2) return and (3) search parameters to index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-5037

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
0
Attacker Value
Unknown

CVE-2008-5195

Disclosure Date: November 21, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in SebracCMS (sbcms) 0.4 allow remote attackers to execute arbitrary SQL commands via (1) the recid parameter to cms/form/read.php, (2) the uname parameter to cms/index.php, and other unspecified vectors.
0