Show filters
63 Total Results
Displaying 41-50 of 63
Sort by:
Attacker Value
Unknown

CVE-2022-45529

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.
Attacker Value
Unknown

CVE-2022-45330

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.
Attacker Value
Unknown

CVE-2022-45331

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.
Attacker Value
Unknown

CVE-2022-38305

Disclosure Date: September 13, 2022 (last updated February 24, 2025)
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2014-3650

Disclosure Date: July 01, 2022 (last updated February 24, 2025)
Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input.
Attacker Value
Unknown

CVE-2014-3648

Disclosure Date: July 01, 2022 (last updated February 24, 2025)
The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceTokens, one can generate endless exceptions when those endpoints can't be reached or can slow the server down by purposefully wasting it's time with slow endpoints. Similarly, one can provide whatever HTTP end point they want. This turns the server into a DDOS vector or an anonymizer for the posting of malware and so on.
Attacker Value
Unknown

CVE-2021-39298

Disclosure Date: May 10, 2022 (last updated November 08, 2023)
A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.
Attacker Value
Unknown

CVE-2022-27063

Disclosure Date: April 08, 2022 (last updated February 23, 2025)
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.
Attacker Value
Unknown

CVE-2022-27062

Disclosure Date: April 08, 2022 (last updated February 23, 2025)
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.
Attacker Value
Unknown

CVE-2022-27061

Disclosure Date: April 08, 2022 (last updated February 23, 2025)
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.