Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2024-10758
Disclosure Date: November 04, 2024 (last updated November 06, 2024)
A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument user_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is distributed under two entirely different names.
0
Attacker Value
Unknown
CVE-2023-31816
Disclosure Date: May 22, 2023 (last updated October 08, 2023)
IT Sourcecode Content Management System Project In PHP and MySQL With Source Code 1.0.0 is vulnerable to Cross Site Scripting (XSS) via /ecodesource/search_list.php.
0
Attacker Value
Unknown
CVE-2022-26615
Disclosure Date: April 05, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields.
0
Attacker Value
Unknown
CVE-2021-25197
Disclosure Date: July 22, 2021 (last updated November 28, 2024)
Cross-site scripting (XSS) vulnerability in SourceCodester Content Management System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter to content_management_system\admin\new_content.php
0
Attacker Value
Unknown
CVE-2014-9343
Disclosure Date: December 08, 2014 (last updated October 05, 2023)
Open redirect vulnerability in modules/system/controller/selectlanguage.class.php in Snowfox CMS 1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the rd parameter in a submit action to snowfox/.
0
Attacker Value
Unknown
CVE-2010-4332
Disclosure Date: December 22, 2010 (last updated October 04, 2023)
Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies.
0
Attacker Value
Unknown
CVE-2007-2106
Disclosure Date: April 18, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Kai Content Management System (K-CMS) 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the current_theme parameter.
0