Show filters
106 Total Results
Displaying 61-70 of 106
Sort by:
Attacker Value
Unknown
CVE-2019-7570
Disclosure Date: February 07, 2019 (last updated November 27, 2024)
A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.
0
Attacker Value
Unknown
CVE-2018-19893
Disclosure Date: December 06, 2018 (last updated November 27, 2024)
SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string.
0
Attacker Value
Unknown
CVE-2018-19595
Disclosure Date: November 27, 2018 (last updated November 27, 2024)
PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/list/5/?current={pboot:if(evAl($_GET[a]))}1{/pboot:if}&a=phpinfo(); URI, because of an incorrect apps\home\controller\ParserController.php parserIfLabel protection mechanism.
0
Attacker Value
Unknown
CVE-2018-19554
Disclosure Date: November 26, 2018 (last updated November 08, 2023)
An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcms/dijit/image/image_tool.jsp.
0
Attacker Value
Unknown
CVE-2018-19053
Disclosure Date: November 07, 2018 (last updated November 27, 2024)
PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, followed by a SELECT statement containing this PHP code.
0
Attacker Value
Unknown
CVE-2018-18450
Disclosure Date: October 17, 2018 (last updated November 27, 2024)
apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/1/id/3 URI.
0
Attacker Value
Unknown
CVE-2018-18211
Disclosure Date: October 10, 2018 (last updated November 27, 2024)
PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.
0
Attacker Value
Unknown
CVE-2018-17364
Disclosure Date: September 23, 2018 (last updated November 27, 2024)
OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.
0
Attacker Value
Unknown
CVE-2018-17085
Disclosure Date: September 16, 2018 (last updated November 27, 2024)
An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr.
0
Attacker Value
Unknown
CVE-2018-17086
Disclosure Date: September 16, 2018 (last updated November 27, 2024)
An issue was discovered in OTCMS 3.61. XSS exists in admin/share_switch.php via these parameters: fieldName fieldName2 tabName.
0