Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2023-50162

Disclosure Date: January 09, 2024 (last updated January 12, 2024)
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.
Attacker Value
Unknown

CVE-2023-50073

Disclosure Date: December 14, 2023 (last updated December 19, 2023)
EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.
Attacker Value
Unknown

CVE-2022-28585

Disclosure Date: May 03, 2022 (last updated October 07, 2023)
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
Attacker Value
Unknown

CVE-2020-22937

Disclosure Date: August 17, 2021 (last updated February 23, 2025)
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
Attacker Value
Unknown

CVE-2019-12362

Disclosure Date: May 27, 2019 (last updated November 27, 2024)
EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.
0
Attacker Value
Unknown

CVE-2019-12361

Disclosure Date: May 27, 2019 (last updated November 27, 2024)
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.
0
Attacker Value
Unknown

CVE-2018-18449

Disclosure Date: March 07, 2019 (last updated November 27, 2024)
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.
0
Attacker Value
Unknown

CVE-2018-20300

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
0
Attacker Value
Unknown

CVE-2018-18869

Disclosure Date: October 31, 2018 (last updated November 27, 2024)
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.
0
Attacker Value
Unknown

CVE-2018-18086

Disclosure Date: October 09, 2018 (last updated November 27, 2024)
EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.
0