Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown

CVE-2019-12362

Disclosure Date: May 27, 2019 (last updated November 27, 2024)
EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.
0
Attacker Value
Unknown

CVE-2019-12361

Disclosure Date: May 27, 2019 (last updated November 27, 2024)
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.
0
Attacker Value
Unknown

CVE-2018-18449

Disclosure Date: March 07, 2019 (last updated November 27, 2024)
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.
0
Attacker Value
Unknown

CVE-2018-20300

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
0
Attacker Value
Unknown

CVE-2018-18869

Disclosure Date: October 31, 2018 (last updated November 27, 2024)
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.
0
Attacker Value
Unknown

CVE-2018-18086

Disclosure Date: October 09, 2018 (last updated November 27, 2024)
EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.
0
Attacker Value
Unknown

CVE-2018-17070

Disclosure Date: September 15, 2018 (last updated November 27, 2024)
An issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via ?q=admin%2Fconfig%2Fsystem%2Fsite-information&render=overlay&render=overlay.
0
Attacker Value
Unknown

CVE-2018-17069

Disclosure Date: September 15, 2018 (last updated November 27, 2024)
An issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay&render=overlay.
0
Attacker Value
Unknown

CVE-2016-10165

Disclosure Date: February 03, 2017 (last updated December 21, 2023)
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
Attacker Value
Unknown

CVE-2008-1613

Disclosure Date: April 22, 2008 (last updated October 04, 2023)
SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and 7.0, allows remote attackers to execute arbitrary SQL commands via the LngId parameter.
0