Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2021-42645

Disclosure Date: May 10, 2022 (last updated February 23, 2025)
CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable host.
Attacker Value
Unknown

CVE-2021-43741

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution.
Attacker Value
Unknown

CVE-2021-43742

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.
Attacker Value
Unknown

CVE-2018-19507

Disclosure Date: December 19, 2018 (last updated November 27, 2024)
CMSimple 4.7.5 has XSS via an admin's use of a ?file=config&action=array URI.
0
Attacker Value
Unknown

CVE-2018-19508

Disclosure Date: December 19, 2018 (last updated November 27, 2024)
CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI.
0
Attacker Value
Unknown

CVE-2014-2219

Disclosure Date: March 20, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in whizzywig/wb.php in CMSimple Classic 3.54 and earlier, possibly as downloaded before February 26, 2014, allows remote attackers to inject arbitrary web script or HTML via the d parameter.
0
Attacker Value
Unknown

CVE-2008-2650

Disclosure Date: June 10, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sl parameter to index.php. NOTE: this can be leveraged for remote file execution by including adm.php and then invoking the upload action. NOTE: on 20080601, the vendor patched 3.1 without changing the version number.
0