Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2020-18282
Disclosure Date: May 08, 2023 (last updated February 24, 2025)
Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature.
0
Attacker Value
Unknown
CVE-2020-18646
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".
0
Attacker Value
Unknown
CVE-2020-18647
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".
0
Attacker Value
Unknown
CVE-2020-23376
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be injected with arbitrary web script or HTML via the name parameter to launch a stored XSS attack.
0
Attacker Value
Unknown
CVE-2020-23373
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter.
0
Attacker Value
Unknown
CVE-2020-23371
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attackers to inject arbitrary web script or HTML via the movieName parameter.
0
Attacker Value
Unknown
CVE-2020-23374
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter.
0
Attacker Value
Unknown
CVE-2019-16721
Disclosure Date: September 23, 2019 (last updated November 27, 2024)
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
0
Attacker Value
Unknown
CVE-2018-20062
Disclosure Date: December 11, 2018 (last updated July 26, 2024)
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string.
0
Attacker Value
Unknown
CVE-2018-7219
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/index.php/admin/admin/edit.html request.
0