Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2017-1000428
Disclosure Date: January 10, 2018 (last updated November 26, 2024)
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string.
0
Attacker Value
Unknown
CVE-2017-9451
Disclosure Date: June 06, 2017 (last updated November 26, 2024)
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.
0
Attacker Value
Unknown
CVE-2017-7878
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database.
0
Attacker Value
Unknown
CVE-2017-7877
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.
0
Attacker Value
Unknown
CVE-2017-7879
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.
0