Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2022-23358

Disclosure Date: February 16, 2022 (last updated October 07, 2023)
EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.
Attacker Value
Unknown

CVE-2020-24271

Disclosure Date: February 01, 2021 (last updated February 22, 2025)
A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent, then post username=***&password=***.
Attacker Value
Unknown

CVE-2019-6294

Disclosure Date: January 15, 2019 (last updated November 27, 2024)
An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbackType/closeCurrent URI.
0
Attacker Value
Unknown

CVE-2018-17113

Disclosure Date: September 17, 2018 (last updated November 27, 2024)
App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter, a related issue to CVE-2018-9173.
0
Attacker Value
Unknown

CVE-2018-16773

Disclosure Date: September 10, 2018 (last updated November 27, 2024)
EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content field.
0
Attacker Value
Unknown

CVE-2018-16759

Disclosure Date: September 09, 2018 (last updated November 27, 2024)
The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via an onhashchange event.
0
Attacker Value
Unknown

CVE-2018-16345

Disclosure Date: September 02, 2018 (last updated November 27, 2024)
An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/admin/rbacuser/update/navTabId/listusers/callbackType/closeCurrent.
0
Attacker Value
Unknown

CVE-2018-12971

Disclosure Date: June 29, 2018 (last updated November 26, 2024)
EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.
0
Attacker Value
Unknown

CVE-2018-10527

Disclosure Date: April 28, 2018 (last updated November 26, 2024)
EasyCMS 1.3 is prone to Stored XSS when posting an article; four fields are affected: title, keyword, abstract, and content, as demonstrated by the /admin/index/index.html#listarticle URI.
0
Attacker Value
Unknown

CVE-2018-10374

Disclosure Date: April 25, 2018 (last updated November 26, 2024)
EasyCMS 1.3 has XSS via the s POST parameter (aka a search box value) in an index.php?s=/index/search/index.html request.
0