Avaterxxx
Products
10- 6 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
17| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-16731 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2018 | CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data. | ||
| CVE-2018-17836 | Hig | 0.57 | 8.8 | 0.02 | Oct 1, 2018 | An issue was discovered in JTBC(PHP) 3.0.1.6. It allows remote attackers to execute arbitrary PHP code by using a /console/file/manage.php?type=action&action=addfile&path=..%2F substring to upload, in conjunction with a multipart/form-data PHP payload. | ||
| CVE-2018-14978 | Hig | 0.57 | 8.8 | 0.00 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI. | ||
| CVE-2018-14966 | Hig | 0.57 | 8.8 | 0.00 | Aug 6, 2018 | An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=user&do=add page allows CSRF. | ||
| CVE-2018-20614 | Hig | 0.49 | 7.5 | 0.01 | Dec 30, 2018 | public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI. | ||
| CVE-2018-20602 | Hig | 0.49 | 7.5 | 0.01 | Dec 30, 2018 | Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI. | ||
| CVE-2018-18737 | Hig | 0.49 | 7.5 | 0.01 | Oct 29, 2018 | An XXE issue was discovered in Douchat 4.0.4 because Data\notify.php calls simplexml_load_string. This can also be used for SSRF. | ||
| CVE-2018-17838 | Hig | 0.49 | 7.5 | 0.02 | Oct 1, 2018 | An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring. | ||
| CVE-2018-19193 | Med | 0.40 | 6.1 | 0.01 | Nov 12, 2018 | An issue was discovered in XiaoCms 20141229. There is XSS via the largest input box on the "New news" screen. | ||
| CVE-2018-18736 | Med | 0.35 | 5.4 | 0.01 | Oct 29, 2018 | An XSS issue was discovered in catfish blog 2.0.33, related to "write source code." | ||
| CVE-2018-14964 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2018 | An issue was discovered in EMLsoft 5.4.5. XSS exists via the eml/upload/eml/?action=address&do=edit page. | ||
| CVE-2018-14962 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2018 | zzcms 8.3 has stored XSS related to the content variable in user/manage.php and zt/show.php. | ||
| CVE-2018-14976 | Med | 0.31 | 4.8 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS. | ||
| CVE-2018-14974 | Med | 0.31 | 4.8 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS. | ||
| CVE-2018-14972 | Med | 0.31 | 4.8 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS. | ||
| CVE-2018-14971 | Med | 0.31 | 4.8 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS. | ||
| CVE-2018-14969 | Med | 0.31 | 4.8 | 0.01 | Aug 6, 2018 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS. |
- risk 0.64cvss 9.8epss 0.01
CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in JTBC(PHP) 3.0.1.6. It allows remote attackers to execute arbitrary PHP code by using a /console/file/manage.php?type=action&action=addfile&path=..%2F substring to upload, in conjunction with a multipart/form-data PHP payload.
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI.
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=user&do=add page allows CSRF.
- risk 0.49cvss 7.5epss 0.01
public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI.
- risk 0.49cvss 7.5epss 0.01
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI.
- risk 0.49cvss 7.5epss 0.01
An XXE issue was discovered in Douchat 4.0.4 because Data\notify.php calls simplexml_load_string. This can also be used for SSRF.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in XiaoCms 20141229. There is XSS via the largest input box on the "New news" screen.
- risk 0.35cvss 5.4epss 0.01
An XSS issue was discovered in catfish blog 2.0.33, related to "write source code."
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in EMLsoft 5.4.5. XSS exists via the eml/upload/eml/?action=address&do=edit page.
- risk 0.35cvss 5.4epss 0.01
zzcms 8.3 has stored XSS related to the content variable in user/manage.php and zt/show.php.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS.
- risk 0.31cvss 4.8epss 0.01
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS.