Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2023-36291

Disclosure Date: July 03, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file.
Attacker Value
Unknown

CVE-2022-25413

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.
Attacker Value
Unknown

CVE-2022-25412

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.
Attacker Value
Unknown

CVE-2022-25411

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-25410

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files.
Attacker Value
Unknown

CVE-2021-27983

Disclosure Date: December 10, 2021 (last updated October 07, 2023)
Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
Attacker Value
Unknown

CVE-2021-35265

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.
Attacker Value
Unknown

CVE-2012-6498

Disclosure Date: January 08, 2013 (last updated October 05, 2023)
Unrestricted file upload vulnerability in index.php in Atomymaxsite 2.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file, as exploited in the wild in October 2012.
0
Attacker Value
Unknown

CVE-2008-6446

Disclosure Date: March 09, 2009 (last updated October 04, 2023)
Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrary PHP code into the guestbook via the message parameter.
0
Attacker Value
Unknown

CVE-2008-2487

Disclosure Date: May 28, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a webboard action.
0