Show filters
102 Total Results
Displaying 71-80 of 102
Sort by:
Attacker Value
Unknown
CVE-2018-11369
Disclosure Date: May 22, 2018 (last updated November 26, 2024)
An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter.
0
Attacker Value
Unknown
CVE-2018-11018
Disclosure Date: May 13, 2018 (last updated November 26, 2024)
An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php allows remote attackers to add administrator accounts via admin.php/role/add.html.
0
Attacker Value
Unknown
CVE-2018-10133
Disclosure Date: April 16, 2018 (last updated November 26, 2024)
PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel function in \apps\home\controller\ParserController.php.
0
Attacker Value
Unknown
CVE-2018-10132
Disclosure Date: April 16, 2018 (last updated November 26, 2024)
PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontent parameter.
0
Attacker Value
Unknown
CVE-2018-8973
Disclosure Date: March 24, 2018 (last updated November 26, 2024)
OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request.
0
Attacker Value
Unknown
CVE-2016-10007
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.
0
Attacker Value
Unknown
CVE-2016-10008
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.
0
Attacker Value
Unknown
CVE-2017-15219
Disclosure Date: October 10, 2017 (last updated November 26, 2024)
The dotCMS 4.1.1 application is vulnerable to Stored Cross-Site Scripting (XSS) affecting a vanity-urls Title field, a containers Description field, and a templates Description field.
0
Attacker Value
Unknown
CVE-2017-11466
Disclosure Date: July 20, 2017 (last updated November 26, 2024)
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrators to upload .jsp files to arbitrary locations via directory traversal sequences in the fieldName parameter to servlets/ajax_file_upload. This results in arbitrary code execution by requesting the .jsp file at a /assets URI.
0
Attacker Value
Unknown
CVE-2017-6003
Disclosure Date: March 27, 2017 (last updated November 26, 2024)
dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.
0