Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
High
CVE-2020-7357
Disclosure Date: April 06, 2020 (last updated February 21, 2025)
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.
0
Attacker Value
Unknown
CVE-2023-50162
Disclosure Date: January 09, 2024 (last updated January 12, 2024)
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.
0
Attacker Value
Unknown
CVE-2023-50073
Disclosure Date: December 14, 2023 (last updated December 19, 2023)
EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.
0
Attacker Value
Unknown
CVE-2023-33604
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
Imperial CMS v7.5 was discovered to contain an arbitrary file deletion vulnerability via the DelspReFile function in /sp/ListSp.php. This vulnerability is exploited by attackers via a crafted POST request.
0
Attacker Value
Unknown
CVE-2022-28585
Disclosure Date: May 03, 2022 (last updated October 07, 2023)
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
0
Attacker Value
Unknown
CVE-2021-36547
Disclosure Date: October 28, 2021 (last updated November 28, 2024)
A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2020-25422
Disclosure Date: October 28, 2021 (last updated November 29, 2024)
A cross site scripting (XSS) vulnerability in menuedit.php of Mara CMS 7.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
0
Attacker Value
Unknown
CVE-2020-36493
Disclosure Date: October 22, 2021 (last updated November 29, 2024)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
0
Attacker Value
Unknown
CVE-2020-23046
Disclosure Date: October 22, 2021 (last updated November 29, 2024)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tpl.php via the `filename`, `mid`, `userid`, and `templet' parameters.
0
Attacker Value
Unknown
CVE-2020-36497
Disclosure Date: October 22, 2021 (last updated November 29, 2024)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters.
0