Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2018-7448
Disclosure Date: February 26, 2018 (last updated November 26, 2024)
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.
0
Attacker Value
Unknown
CVE-2017-16783
Disclosure Date: November 10, 2017 (last updated November 26, 2024)
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
0
Attacker Value
Unknown
CVE-2017-9668
Disclosure Date: June 18, 2017 (last updated November 26, 2024)
In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user group, there is no XSS filtering, resulting in storage-type XSS generation, via the description parameter in an addgroup action.
0
Attacker Value
Unknown
CVE-2017-8912
Disclosure Date: May 12, 2017 (last updated November 08, 2023)
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is "a feature, not a bug.
0
Attacker Value
Unknown
CVE-2017-7256
Disclosure Date: March 24, 2017 (last updated February 15, 2024)
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_summary parameter. Someone must login to conduct the attack.
0
Attacker Value
Unknown
CVE-2017-7255
Disclosure Date: March 24, 2017 (last updated February 15, 2024)
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_title parameter. Someone must login to conduct the attack.
0
Attacker Value
Unknown
CVE-2017-7257
Disclosure Date: March 24, 2017 (last updated February 15, 2024)
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Someone must login to conduct the attack.
0
Attacker Value
Unknown
CVE-2017-6555
Disclosure Date: March 09, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in /admin/moduleinterface.php in CMS Made Simple 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the m1_description parameter (aka "Design Manager > Categories > Category Description").
0
Attacker Value
Unknown
CVE-2017-6556
Disclosure Date: March 09, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings > globalmetadata" field.
0
Attacker Value
Unknown
CVE-2016-2784
Disclosure Date: May 26, 2016 (last updated November 25, 2024)
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.
0