Show filters
42 Total Results
Displaying 31-40 of 42
Sort by:
Attacker Value
Unknown
CVE-2018-11475
Disclosure Date: May 25, 2018 (last updated November 26, 2024)
Monstra CMS 3.0.4 has a Session Management Issue in the Users tab. A password change at users/1/edit does not invalidate a session that is open in a different browser.
0
Attacker Value
Unknown
CVE-2018-11474
Disclosure Date: May 25, 2018 (last updated November 26, 2024)
Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab. A password change at admin/index.php?id=users&action=edit&user_id=1 does not invalidate a session that is open in a different browser.
0
Attacker Value
Unknown
CVE-2018-11473
Disclosure Date: May 25, 2018 (last updated November 26, 2024)
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
0
Attacker Value
Unknown
CVE-2018-10121
Disclosure Date: April 16, 2018 (last updated November 26, 2024)
plugins/box/pages/pages.admin.php in Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the title section of an admin/index.php?id=pages&action=edit_page&name=error404 (aka Edit 404 page) action.
0
Attacker Value
Unknown
CVE-2018-10109
Disclosure Date: April 16, 2018 (last updated November 26, 2024)
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the content section of a new page in the blog catalog.
0
Attacker Value
Unknown
CVE-2018-10118
Disclosure Date: April 16, 2018 (last updated November 26, 2024)
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI, related to plugins/box/pages/pages.admin.php.
0
Attacker Value
Unknown
CVE-2018-9037
Disclosure Date: April 10, 2018 (last updated November 26, 2024)
Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain .php files.
0
Attacker Value
Unknown
CVE-2018-9038
Disclosure Date: April 10, 2018 (last updated November 26, 2024)
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.
0
Attacker Value
Unknown
CVE-2018-6550
Disclosure Date: February 02, 2018 (last updated November 26, 2024)
Monstra CMS through 3.0.4 has XSS in the title function in plugins/box/pages/pages.plugin.php via a page title to admin/index.php.
0
Attacker Value
Unknown
CVE-2018-6383
Disclosure Date: January 29, 2018 (last updated November 26, 2024)
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated Admins or Editors to execute arbitrary PHP code by uploading a file, a different vulnerability than CVE-2017-18048.
0