VYPR
Vendor

Avaterxxx

Products
5
CVEs
12
Across products
11
Status
Private

Products

5

Recent CVEs

12
  • CVE-2018-16731CriSep 8, 2018
    risk 0.64cvss 9.8epss 0.01

    CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.

  • CVE-2018-17836HigOct 1, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in JTBC(PHP) 3.0.1.6. It allows remote attackers to execute arbitrary PHP code by using a /console/file/manage.php?type=action&action=addfile&path=..%2F substring to upload, in conjunction with a multipart/form-data PHP payload.

  • CVE-2018-14978HigAug 6, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI.

  • CVE-2018-14966HigAug 6, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=user&do=add page allows CSRF.

  • CVE-2018-17838HigOct 1, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring.

  • CVE-2018-14964MedAug 6, 2018
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in EMLsoft 5.4.5. XSS exists via the eml/upload/eml/?action=address&do=edit page.

  • CVE-2018-14962MedAug 6, 2018
    risk 0.35cvss 5.4epss 0.01

    zzcms 8.3 has stored XSS related to the content variable in user/manage.php and zt/show.php.

  • CVE-2018-14976MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS.

  • CVE-2018-14974MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS.

  • CVE-2018-14972MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS.

  • CVE-2018-14971MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS.

  • CVE-2018-14969MedAug 6, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS.