Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2023-29854

Disclosure Date: April 18, 2023 (last updated October 08, 2023)
DirCMS 6.0.0 has a Cross Site Scripting (XSS) vulnerability in the foreground.
Attacker Value
Unknown

CVE-2022-36226

Disclosure Date: August 26, 2022 (last updated February 24, 2025)
SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.
Attacker Value
Unknown

CVE-2021-36605

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
engineercms 1.03 is vulnerable to Cross Site Scripting (XSS). There is no escaping in the nickname field on the user list page. When viewing this page, the JavaScript code will be executed in the user's browser.
Attacker Value
Unknown

CVE-2020-13427

Disclosure Date: June 22, 2020 (last updated February 21, 2025)
Victor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname parameter.
Attacker Value
Unknown

CVE-2018-19557

Disclosure Date: November 26, 2018 (last updated November 27, 2024)
An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/images.
0
Attacker Value
Unknown

CVE-2018-19558

Disclosure Date: November 26, 2018 (last updated November 27, 2024)
An issue was discovered in arcms through 2018-03-19. SQL injection exists via the json/newslist limit parameter because of ctl/main/Json.php, ctl/main/service/Data.php, and comp/Db/Mysql.php.
0
Attacker Value
Unknown

CVE-2018-19319

Disclosure Date: November 16, 2018 (last updated November 27, 2024)
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.
0
Attacker Value
Unknown

CVE-2018-19318

Disclosure Date: November 16, 2018 (last updated November 27, 2024)
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account.
0
Attacker Value
Unknown

CVE-2018-15846

Disclosure Date: August 25, 2018 (last updated November 27, 2024)
An issue was discovered in fledrCMS through 2014-02-03. There is a CSRF vulnerability that can change the administrator's password via index.php?p=done&savedata=1.
0
Attacker Value
Unknown

CVE-2018-14068

Disclosure Date: July 15, 2018 (last updated November 27, 2024)
An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add an admin account via admin.php?m=Admin&c=manager&a=add.
0