Show filters
49 Total Results
Displaying 41-49 of 49
Sort by:
Attacker Value
Unknown
CVE-2021-37262
Disclosure Date: December 16, 2021 (last updated February 23, 2025)
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.
0
Attacker Value
Unknown
CVE-2021-40639
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
0
Attacker Value
Unknown
CVE-2020-19151
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.
0
Attacker Value
Unknown
CVE-2020-19150
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.
0
Attacker Value
Unknown
CVE-2020-19154
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.
0
Attacker Value
Unknown
CVE-2020-19148
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.
0
Attacker Value
Unknown
CVE-2020-19155
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.
0
Attacker Value
Unknown
CVE-2020-19146
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.
0
Attacker Value
Unknown
CVE-2020-19147
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.
0