|
246101
|
8.8 |
HIGH
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-14978
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246102
|
6.1 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/guest.php has XSS, as demonstrated by the name parameter, a different vulnerability than CVE-2018-8070.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14977
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246103
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14976
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246104
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/album.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14975
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246105
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14974
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246106
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14973
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246107
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14972
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246108
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14971
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246109
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14970
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246110
|
4.8 |
MEDIUM
Network
|
q-cms
|
qcms
|
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14969
|
2024-11-21 12:50 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|