Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
High

CVE-2020-7357

Disclosure Date: April 06, 2020 (last updated February 21, 2025)
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.
Attacker Value
Unknown

CVE-2023-50162

Disclosure Date: January 09, 2024 (last updated January 12, 2024)
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.
Attacker Value
Unknown

CVE-2023-50073

Disclosure Date: December 14, 2023 (last updated December 19, 2023)
EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.
Attacker Value
Unknown

CVE-2023-33604

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
Imperial CMS v7.5 was discovered to contain an arbitrary file deletion vulnerability via the DelspReFile function in /sp/ListSp.php. This vulnerability is exploited by attackers via a crafted POST request.
Attacker Value
Unknown

CVE-2022-28585

Disclosure Date: May 03, 2022 (last updated October 07, 2023)
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
Attacker Value
Unknown

CVE-2021-36547

Disclosure Date: October 28, 2021 (last updated November 28, 2024)
A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file.
Attacker Value
Unknown

CVE-2020-25422

Disclosure Date: October 28, 2021 (last updated November 29, 2024)
A cross site scripting (XSS) vulnerability in menuedit.php of Mara CMS 7.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Attacker Value
Unknown

CVE-2020-36493

Disclosure Date: October 22, 2021 (last updated November 29, 2024)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
Attacker Value
Unknown

CVE-2020-23046

Disclosure Date: October 22, 2021 (last updated November 29, 2024)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tpl.php via the `filename`, `mid`, `userid`, and `templet' parameters.
Attacker Value
Unknown

CVE-2020-36497

Disclosure Date: October 22, 2021 (last updated November 29, 2024)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters.