Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2019-10766
Disclosure Date: November 19, 2019 (last updated November 27, 2024)
Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.
0
Attacker Value
Unknown
CVE-2017-12905
Disclosure Date: September 25, 2017 (last updated November 26, 2024)
Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrary code via the url parameter to Launderer.php.
0
Attacker Value
Unknown
CVE-2017-7402
Disclosure Date: April 03, 2017 (last updated November 26, 2024)
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.
0
Attacker Value
Unknown
CVE-2017-7361
Disclosure Date: March 31, 2017 (last updated November 26, 2024)
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.
0
Attacker Value
Unknown
CVE-2017-7360
Disclosure Date: March 31, 2017 (last updated November 26, 2024)
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.
0
Attacker Value
Unknown
CVE-2017-7359
Disclosure Date: March 31, 2017 (last updated November 26, 2024)
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.
0
Attacker Value
Unknown
CVE-2017-7362
Disclosure Date: March 31, 2017 (last updated November 26, 2024)
Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.
0
Attacker Value
Unknown
CVE-2017-7363
Disclosure Date: March 31, 2017 (last updated November 26, 2024)
Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack.
0
Attacker Value
Unknown
CVE-2014-3786
Disclosure Date: June 04, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitrary web script or HTML via the (1) uemail or (2) subject parameter in the Contact form to contact/.
0
Attacker Value
Unknown
CVE-2011-4710
Disclosure Date: December 08, 2011 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI.
0