Show filters
35 Total Results
Displaying 21-30 of 35
Sort by:
Attacker Value
Unknown
CVE-2020-21564
Disclosure Date: September 30, 2020 (last updated February 22, 2025)
An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.
0
Attacker Value
Unknown
CVE-2019-11344
Disclosure Date: April 19, 2019 (last updated November 27, 2024)
data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked.
0
Attacker Value
Unknown
CVE-2019-9048
Disclosure Date: February 23, 2019 (last updated November 27, 2024)
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI.
0
Attacker Value
Unknown
CVE-2019-9050
Disclosure Date: February 23, 2019 (last updated November 27, 2024)
An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive, which is then extracted and executed.
0
Attacker Value
Unknown
CVE-2019-9051
Disclosure Date: February 23, 2019 (last updated November 27, 2024)
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI.
0
Attacker Value
Unknown
CVE-2019-9049
Disclosure Date: February 23, 2019 (last updated November 27, 2024)
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI.
0
Attacker Value
Unknown
CVE-2019-9052
Disclosure Date: February 23, 2019 (last updated November 27, 2024)
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI.
0
Attacker Value
Unknown
CVE-2018-16633
Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title.
0
Attacker Value
Unknown
CVE-2018-16634
Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Pluck v4.7.7 allows CSRF via admin.php?action=settings.
0
Attacker Value
Unknown
CVE-2018-16729
Disclosure Date: September 12, 2018 (last updated November 27, 2024)
Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files.
0