Show filters
42 Total Results
Displaying 41-42 of 42
Sort by:
Attacker Value
Unknown
CVE-2017-18048
Disclosure Date: January 23, 2018 (last updated November 26, 2024)
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.
0
Attacker Value
Unknown
CVE-2014-9006
Disclosure Date: November 20, 2014 (last updated October 05, 2023)
Monstra 3.0.1 and earlier uses a cookie to track how many login attempts have been attempted, which allows remote attackers to conduct brute force login attacks by deleting the login_attempts cookie or setting it to certain values.
0