Show filters
33 Total Results
Displaying 31-33 of 33
Sort by:
Attacker Value
Unknown
CVE-2017-9252
Disclosure Date: May 28, 2017 (last updated February 15, 2024)
andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the search page via the text-search parameter to index.php in a route=search action.
0
Attacker Value
Unknown
CVE-2017-9251
Disclosure Date: May 28, 2017 (last updated February 15, 2024)
andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the sitename parameter to admin.php.
0
Attacker Value
Unknown
CVE-2017-6511
Disclosure Date: March 07, 2017 (last updated November 26, 2024)
andrzuk/FineCMS before 2017-03-06 is vulnerable to a reflected XSS in index.php because of missing validation of the action parameter in application/classes/application.php.
0