Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown
CVE-2019-12362
Disclosure Date: May 27, 2019 (last updated November 27, 2024)
EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.
0
Attacker Value
Unknown
CVE-2019-12361
Disclosure Date: May 27, 2019 (last updated November 27, 2024)
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.
0
Attacker Value
Unknown
CVE-2018-18449
Disclosure Date: March 07, 2019 (last updated November 27, 2024)
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.
0
Attacker Value
Unknown
CVE-2018-20300
Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
0
Attacker Value
Unknown
CVE-2018-18869
Disclosure Date: October 31, 2018 (last updated November 27, 2024)
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.
0
Attacker Value
Unknown
CVE-2018-18086
Disclosure Date: October 09, 2018 (last updated November 27, 2024)
EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.
0
Attacker Value
Unknown
CVE-2018-17070
Disclosure Date: September 15, 2018 (last updated November 27, 2024)
An issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via ?q=admin%2Fconfig%2Fsystem%2Fsite-information&render=overlay&render=overlay.
0
Attacker Value
Unknown
CVE-2018-17069
Disclosure Date: September 15, 2018 (last updated November 27, 2024)
An issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay&render=overlay.
0
Attacker Value
Unknown
CVE-2016-10165
Disclosure Date: February 03, 2017 (last updated December 21, 2023)
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
0
Attacker Value
Unknown
CVE-2008-1613
Disclosure Date: April 22, 2008 (last updated October 04, 2023)
SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and 7.0, allows remote attackers to execute arbitrary SQL commands via the LngId parameter.
0