Show filters
106 Total Results
Displaying 71-80 of 106
Sort by:
Attacker Value
Unknown
CVE-2018-16980
Disclosure Date: September 12, 2018 (last updated November 27, 2024)
dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.
0
Attacker Value
Unknown
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" …
Disclosure Date: July 24, 2018 (last updated November 27, 2024)
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to path traversal. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, the filenames of its contents are not properly checked, allowing for writing files to arbitrary directories on the file system. These archives may be uploaded directly via the administrator panel, or using the CSRF vulnerability (CVE-2017-3187). An unauthenticated remote attacker may perform actions with the dotCMS administrator panel with the same permissions of a victim user or execute arbitrary system commands with the permissions of the user running the dotCMS application.
0
Attacker Value
Unknown
The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to …
Disclosure Date: July 24, 2018 (last updated November 27, 2024)
The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS administrator panel contains a cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request. An unauthenticated remote attacker may perform actions with the dotCMS administrator panel with the same permissions of a victim user or execute arbitrary system commands with the permissions of the user running the dotCMS application.
0
Attacker Value
Unknown
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" …
Disclosure Date: July 24, 2018 (last updated November 27, 2024)
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, there are no checks on the types of files which the bundle contains. This vulnerability combined with the path traversal vulnerability (CVE-2017-3188) can lead to remote command execution with the permissions of the user running the dotCMS application. An unauthenticated remote attacker may perform actions with the dotCMS administrator panel with the same permissions of a victim user or execute arbitrary system commands with the permissions of the user running the dotCMS application.
0
Attacker Value
Unknown
CVE-2018-11369
Disclosure Date: May 22, 2018 (last updated November 26, 2024)
An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter.
0
Attacker Value
Unknown
CVE-2018-11018
Disclosure Date: May 13, 2018 (last updated November 26, 2024)
An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php allows remote attackers to add administrator accounts via admin.php/role/add.html.
0
Attacker Value
Unknown
CVE-2018-10133
Disclosure Date: April 16, 2018 (last updated November 26, 2024)
PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel function in \apps\home\controller\ParserController.php.
0
Attacker Value
Unknown
CVE-2018-10132
Disclosure Date: April 16, 2018 (last updated November 26, 2024)
PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontent parameter.
0
Attacker Value
Unknown
CVE-2018-8973
Disclosure Date: March 24, 2018 (last updated November 26, 2024)
OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request.
0
Attacker Value
Unknown
CVE-2016-10007
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.
0