Icms
by Idreamsoft
Source repositories
CVEs (49)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39806 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function. | ||
| CVE-2023-39805 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php. | ||
| CVE-2022-41496 | Cri | 0.64 | 9.8 | 0.01 | Oct 13, 2022 | iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php. | ||
| CVE-2021-44978 | Cri | 0.64 | 9.8 | 0.02 | Feb 4, 2022 | iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution. | ||
| CVE-2020-19527 | Cri | 0.64 | 9.8 | 0.02 | Dec 10, 2020 | iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php. | ||
| CVE-2020-19142 | Cri | 0.64 | 9.8 | 0.02 | Dec 10, 2020 | iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php. | ||
| CVE-2019-17552 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2019 | An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload. | ||
| CVE-2019-7160 | Cri | 0.64 | 9.8 | 0.03 | Jan 29, 2019 | idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arbitrary PHP code from a ZIP file via the admincp.php?app=apps zipfile parameter to apps.admincp.php. | ||
| CVE-2019-6259 | Cri | 0.64 | 9.8 | 0.02 | Jan 14, 2019 | An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id parameter. | ||
| CVE-2018-18702 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion. | ||
| CVE-2018-14514 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2018 | An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have unspecified other impact. | ||
| CVE-2018-12498 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2018 | spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php. | ||
| CVE-2018-9924 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2018 | An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp.php?app=tag&do=save&frame=iPHP request. | ||
| CVE-2020-18070 | Cri | 0.59 | 9.1 | 0.02 | Apr 30, 2021 | Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to the "do_del()" method of the component "database.admincp.php". | ||
| CVE-2019-7234 | Cri | 0.59 | 9.1 | 0.02 | Jan 30, 2019 | An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to begin the process of creating a ZIP archive file with the complete contents of any directory because of an apps.admincp.php error. This ZIP archive file… | ||
| CVE-2023-40953 | Hig | 0.57 | 8.8 | 0.00 | Sep 8, 2023 | icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF). | ||
| CVE-2020-21141 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2021 | iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add. | ||
| CVE-2020-26641 | Hig | 0.57 | 8.8 | 0.01 | May 28, 2021 | A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts. | ||
| CVE-2018-16366 | Hig | 0.57 | 8.8 | 0.01 | Sep 2, 2018 | An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF. | ||
| CVE-2018-16365 | Hig | 0.57 | 8.8 | 0.01 | Sep 2, 2018 | An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF. |
- risk 0.64cvss 9.8epss 0.01
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
- risk 0.64cvss 9.8epss 0.01
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
- risk 0.64cvss 9.8epss 0.01
iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.
- risk 0.64cvss 9.8epss 0.02
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
- risk 0.64cvss 9.8epss 0.02
iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.
- risk 0.64cvss 9.8epss 0.02
iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
- risk 0.64cvss 9.8epss 0.03
idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arbitrary PHP code from a ZIP file via the admincp.php?app=apps zipfile parameter to apps.admincp.php.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id parameter.
- risk 0.64cvss 9.8epss 0.01
spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion.
- risk 0.64cvss 9.8epss 0.02
An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have unspecified other impact.
- risk 0.64cvss 9.8epss 0.01
spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp.php?app=tag&do=save&frame=iPHP request.
- risk 0.59cvss 9.1epss 0.02
Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to the "do_del()" method of the component "database.admincp.php".
- risk 0.59cvss 9.1epss 0.02
An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to begin the process of creating a ZIP archive file with the complete contents of any directory because of an apps.admincp.php error. This ZIP archive file…
- risk 0.57cvss 8.8epss 0.00
icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).
- risk 0.57cvss 8.8epss 0.01
iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.
- risk 0.57cvss 8.8epss 0.01
A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.
Page 1 of 3