Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2022-23358
Disclosure Date: February 16, 2022 (last updated October 07, 2023)
EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.
0
Attacker Value
Unknown
CVE-2020-24271
Disclosure Date: February 01, 2021 (last updated February 22, 2025)
A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent, then post username=***&password=***.
0
Attacker Value
Unknown
CVE-2019-6294
Disclosure Date: January 15, 2019 (last updated November 27, 2024)
An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbackType/closeCurrent URI.
0
Attacker Value
Unknown
CVE-2018-17113
Disclosure Date: September 17, 2018 (last updated November 27, 2024)
App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter, a related issue to CVE-2018-9173.
0
Attacker Value
Unknown
CVE-2018-16773
Disclosure Date: September 10, 2018 (last updated November 27, 2024)
EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content field.
0
Attacker Value
Unknown
CVE-2018-16759
Disclosure Date: September 09, 2018 (last updated November 27, 2024)
The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via an onhashchange event.
0
Attacker Value
Unknown
CVE-2018-16345
Disclosure Date: September 02, 2018 (last updated November 27, 2024)
An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/admin/rbacuser/update/navTabId/listusers/callbackType/closeCurrent.
0
Attacker Value
Unknown
CVE-2018-12971
Disclosure Date: June 29, 2018 (last updated November 26, 2024)
EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.
0
Attacker Value
Unknown
CVE-2018-10527
Disclosure Date: April 28, 2018 (last updated November 26, 2024)
EasyCMS 1.3 is prone to Stored XSS when posting an article; four fields are affected: title, keyword, abstract, and content, as demonstrated by the /admin/index/index.html#listarticle URI.
0
Attacker Value
Unknown
CVE-2018-10374
Disclosure Date: April 25, 2018 (last updated November 26, 2024)
EasyCMS 1.3 has XSS via the s POST parameter (aka a search box value) in an index.php?s=/index/search/index.html request.
0