VYPR
Vendor

Avaterxxx

Products
10
CVEs
17
Across products
17
Status
Private

Products

10

Recent CVEs

17
  • CVE-2018-16731CriSep 8, 2018
    risk 0.64cvss 9.8epss 0.01

    CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.

  • CVE-2018-17836HigOct 1, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in JTBC(PHP) 3.0.1.6. It allows remote attackers to execute arbitrary PHP code by using a /console/file/manage.php?type=action&action=addfile&path=..%2F substring to upload, in conjunction with a multipart/form-data PHP payload.

  • CVE-2018-14978HigAug 6, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI.

  • CVE-2018-14966HigAug 6, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=user&do=add page allows CSRF.

  • CVE-2018-20614HigDec 30, 2018
    risk 0.49cvss 7.5epss 0.01

    public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI.

  • CVE-2018-20602HigDec 30, 2018
    risk 0.49cvss 7.5epss 0.01

    Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI.

  • CVE-2018-18737HigOct 29, 2018
    risk 0.49cvss 7.5epss 0.01

    An XXE issue was discovered in Douchat 4.0.4 because Data\notify.php calls simplexml_load_string. This can also be used for SSRF.

  • CVE-2018-17838HigOct 1, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring.

  • CVE-2018-19193MedNov 12, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in XiaoCms 20141229. There is XSS via the largest input box on the "New news" screen.

  • CVE-2018-18736MedOct 29, 2018
    risk 0.35cvss 5.4epss 0.01

    An XSS issue was discovered in catfish blog 2.0.33, related to "write source code."

  • CVE-2018-14964MedAug 6, 2018
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in EMLsoft 5.4.5. XSS exists via the eml/upload/eml/?action=address&do=edit page.

  • CVE-2018-14962MedAug 6, 2018
    risk 0.35cvss 5.4epss 0.01

    zzcms 8.3 has stored XSS related to the content variable in user/manage.php and zt/show.php.

  • CVE-2018-14976MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS.

  • CVE-2018-14974MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS.

  • CVE-2018-14972MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS.

  • CVE-2018-14971MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS.

  • CVE-2018-14969MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS.