|
247441
|
4.8 |
MEDIUM
Network
|
seacms
|
seacms
|
SeaCMS V6.61 has XSS via the admin_video.php v_content parameter, related to the site name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16348
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247442
|
6.1 |
MEDIUM
Network
|
gleezcms
|
gleez_cms
|
An issue was discovered in Gleez CMS v1.2.0. There is XSS via media/imagecache/resize.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16347
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247443
|
4.8 |
MEDIUM
Network
|
chemcms_project
|
chemcms
|
ChemCMS 1.0.6 has XSS via the "setting -> website information" field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16346
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247444
|
8.8 |
HIGH
Network
|
easycms
|
easycms
|
An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/admin/rbacuser/update/navTabId/listusers/callbackType/closeCurrent.
|
CWE-352
Origin Validation Error
|
CVE-2018-16345
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247445
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deletin…
|
CWE-22
Path Traversal
|
CVE-2018-16344
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247446
|
7.2 |
HIGH
Network
|
seacms
|
seacms
|
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.
|
CWE-94
Code Injection
|
CVE-2018-16343
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247447
|
5.4 |
MEDIUM
Network
|
showdoc
|
showdoc
|
ShowDoc v1.8.0 has XSS via a new page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16342
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247448
|
8.8 |
HIGH
Network
|
phome
|
empirecms
|
An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.
|
CWE-352
Origin Validation Error
|
CVE-2018-16339
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247449
|
8.8 |
HIGH
Network
|
auracms
|
auracms
|
An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subsequently add a page or menu, or submit a topic.
|
CWE-352
Origin Validation Error
|
CVE-2018-16338
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247450
|
6.5 |
MEDIUM
Network
|
chshcms
|
cscms
|
An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/save.
|
CWE-352
Origin Validation Error
|
CVE-2018-16337
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|