Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2018-16339

Disclosure Date: September 02, 2018 (last updated November 27, 2024)
An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.
0
Attacker Value
Unknown

CVE-2018-6881

Disclosure Date: February 12, 2018 (last updated November 26, 2024)
EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.