|
265151
|
8.8 |
HIGH
Network
|
basercms
|
basercms
|
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4887
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265152
|
8.8 |
HIGH
Network
|
basercms
|
basercms
|
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4886
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265153
|
8.8 |
HIGH
Network
|
basercms
|
basercms
|
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Feed version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4885
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265154
|
8.8 |
HIGH
Network
|
basercms
|
basercms
|
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4884
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265155
|
5.4 |
MEDIUM
Network
|
basercms
|
basercms
|
Cross-site scripting vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4883
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265156
|
8.8 |
HIGH
Network
|
basercms
|
basercms
|
Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4882
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265157
|
8.8 |
HIGH
Network
|
basercms
|
basercms
|
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4881
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265158
|
5.4 |
MEDIUM
Network
|
basercms
|
basercms
|
Cross-site scripting vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4880
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265159
|
8.8 |
HIGH
Network
|
basercms
|
basercms mail
|
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4879
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265160
|
8.8 |
HIGH
Network
|
basercms
|
basercms
|
Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4878
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|