Show filters
99 Total Results
Displaying 91-99 of 99
Sort by:
Attacker Value
Unknown
CVE-2018-13790
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page.
0
Attacker Value
Unknown
CVE-2017-18195
Disclosure Date: February 26, 2018 (last updated November 26, 2024)
An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/required/conversations/view_ajax with incremental 'cnvID' integers.
0
Attacker Value
Unknown
CVE-2015-4721
Disclosure Date: September 07, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1.
0
Attacker Value
Unknown
CVE-2015-4724
Disclosure Date: September 07, 2017 (last updated November 26, 2024)
SQL injection vulnerability in Concrete5 5.7.3.1.
0
Attacker Value
Unknown
CVE-2017-8082
Disclosure Date: April 24, 2017 (last updated November 26, 2024)
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results in a site-wide denial of service making the site not accessible to any users or any administrators.
0
Attacker Value
Unknown
CVE-2017-7725
Disclosure Date: April 13, 2017 (last updated November 26, 2024)
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.
0
Attacker Value
Unknown
CVE-2014-9526
Disclosure Date: January 05, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 5.7.2.1, 5.7.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gName parameter in single_pages/dashboard/users/groups/bulkupdate.php or (2) instance_id parameter in tools/dashboard/sitemap_drag_request.php.
0
Attacker Value
Unknown
CVE-2014-5108
Disclosure Date: July 28, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to index.php/download_file.
0
Attacker Value
Unknown
CVE-2014-5107
Disclosure Date: July 28, 2014 (last updated October 05, 2023)
concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.php, (3) system/environment/file_storage_locations.php, (4) system/mail/importers.php, (5) system/mail/method.php, (6) system/permissions/file_types.php, (7) system/permissions/files.php, (8) system/permissions/tasks.php, (9) system/permissions/users.php, (10) system/seo/view.php, (11) view.php, (12) users/attributes.php, (13) scrapbook/view.php, (14) pages/attributes.php, (15) files/attributes.php, or (16) files/search.php in single_pages/dashboard/.
0