Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2018-7448

Disclosure Date: February 26, 2018 (last updated November 26, 2024)
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.
0
Attacker Value
Unknown

CVE-2017-16783

Disclosure Date: November 10, 2017 (last updated November 26, 2024)
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
Attacker Value
Unknown

CVE-2017-9668

Disclosure Date: June 18, 2017 (last updated November 26, 2024)
In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user group, there is no XSS filtering, resulting in storage-type XSS generation, via the description parameter in an addgroup action.
0
Attacker Value
Unknown

CVE-2017-8912

Disclosure Date: May 12, 2017 (last updated November 08, 2023)
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is "a feature, not a bug.
0
Attacker Value
Unknown

CVE-2017-7256

Disclosure Date: March 24, 2017 (last updated February 15, 2024)
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_summary parameter. Someone must login to conduct the attack.
0
Attacker Value
Unknown

CVE-2017-7255

Disclosure Date: March 24, 2017 (last updated February 15, 2024)
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_title parameter. Someone must login to conduct the attack.
0
Attacker Value
Unknown

CVE-2017-7257

Disclosure Date: March 24, 2017 (last updated February 15, 2024)
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Someone must login to conduct the attack.
0
Attacker Value
Unknown

CVE-2017-6555

Disclosure Date: March 09, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in /admin/moduleinterface.php in CMS Made Simple 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the m1_description parameter (aka "Design Manager > Categories > Category Description").
0
Attacker Value
Unknown

CVE-2017-6556

Disclosure Date: March 09, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings > globalmetadata" field.
0
Attacker Value
Unknown

CVE-2016-2784

Disclosure Date: May 26, 2016 (last updated November 25, 2024)
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.
0