|
246291
|
9.8 |
CRITICAL
Network
|
fhcrm_project
|
fhcrm
|
An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the /index.php/Customer/read limit parameter.
|
CWE-89
SQL Injection
|
CVE-2018-16353
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246292
|
9.8 |
CRITICAL
Network
|
weaselcms_project
|
weaselcms
|
There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a .png file when the image/png content type is used.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-16352
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246293
|
6.1 |
MEDIUM
Network
|
wuzhi_cms_project
|
wuzhi_cms
|
WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16350
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246294
|
6.1 |
MEDIUM
Network
|
wuzhi_cms_project
|
wuzhi_cms
|
WUZHI CMS 4.1.0 has XSS via the index.php?m=link&f=index&v=add form[remark] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16349
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246295
|
4.8 |
MEDIUM
Network
|
seacms
|
seacms
|
SeaCMS V6.61 has XSS via the admin_video.php v_content parameter, related to the site name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16348
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246296
|
6.1 |
MEDIUM
Network
|
gleezcms
|
gleez_cms
|
An issue was discovered in Gleez CMS v1.2.0. There is XSS via media/imagecache/resize.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16347
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246297
|
4.8 |
MEDIUM
Network
|
chemcms_project
|
chemcms
|
ChemCMS 1.0.6 has XSS via the "setting -> website information" field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16346
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246298
|
8.8 |
HIGH
Network
|
easycms
|
easycms
|
An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/admin/rbacuser/update/navTabId/listusers/callbackType/closeCurrent.
|
CWE-352
Origin Validation Error
|
CVE-2018-16345
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246299
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deletin…
|
CWE-22
Path Traversal
|
CVE-2018-16344
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246300
|
7.2 |
HIGH
Network
|
seacms
|
seacms
|
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.
|
CWE-94
Code Injection
|
CVE-2018-16343
|
2024-11-21 12:52 |
2018-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|