Show filters
102 Total Results
Displaying 41-50 of 102
Sort by:
Attacker Value
Unknown

CVE-2021-28245

Disclosure Date: March 31, 2021 (last updated February 22, 2025)
PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account.
Attacker Value
Unknown

CVE-2020-27848

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection attacks. A user must be an authenticated manager in the dotCMS system to exploit this vulnerability.
Attacker Value
Unknown

CVE-2020-35274

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a stored XSS attack and stealing cookies using XSS.
Attacker Value
Unknown

CVE-2020-17901

Disclosure Date: November 30, 2020 (last updated February 22, 2025)
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
Attacker Value
Unknown

CVE-2018-16356

Disclosure Date: March 02, 2020 (last updated February 21, 2025)
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter.
Attacker Value
Unknown

CVE-2018-16357

Disclosure Date: March 02, 2020 (last updated February 21, 2025)
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter.
Attacker Value
Unknown

CVE-2020-6754

Disclosure Date: February 05, 2020 (last updated February 21, 2025)
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp files) into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution (with the permissions of the user running the dotCMS application).
Attacker Value
Unknown

CVE-2019-17417

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.
Attacker Value
Unknown

CVE-2019-17370

Disclosure Date: October 09, 2019 (last updated November 27, 2024)
OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block the "into/**/outfile" manipulation. Therefore, the attacker can create a .php file.
Attacker Value
Unknown

CVE-2019-17369

Disclosure Date: October 09, 2019 (last updated November 27, 2024)
OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superadmin.