Show filters
35 Total Results
Displaying 31-35 of 35
Sort by:
Attacker Value
Unknown
CVE-2018-11736
Disclosure Date: June 05, 2018 (last updated November 26, 2024)
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.
0
Attacker Value
Unknown
CVE-2014-8706
Disclosure Date: March 17, 2017 (last updated November 26, 2024)
Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to an array; or (4) changing the image parameter to a string, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2014-8708
Disclosure Date: March 17, 2017 (last updated November 26, 2024)
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
0
Attacker Value
Unknown
CVE-2014-8707
Disclosure Date: March 17, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbitrary web script or HTML via the "edit HTML source" option.
0
Attacker Value
Unknown
CVE-2012-1227
Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in pluck 4.7 allow remote attackers to hijack the authentication of admins for requests that (1) modify the admin email address or (2) modify the blog title via a settings action; (3) add a page via an editpage action, or (4) add a categorie via the blog module.
0