VYPR
Vendor

Empire CMS

Products
1
CVEs
13
Across products
13
Status
Private

Products

1

Recent CVEs

13
  • CVE-2006-2393May 16, 2006
    risk 0.04cvss epss 0.11

    The client_cmd function in Empire 4.3.2 and earlier allows remote attackers to cause a denial of service (application crash) by causing long text strings to be appended to the player->client buffer, which causes an invalid memory access.

  • CVE-2009-2269Jul 1, 2009
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in Empire CMS 5.1 allows remote attackers to execute arbitrary SQL commands via the bid parameter to the default URI under e/tool/gbook/.

  • CVE-2023-50162Jan 8, 2024
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.

  • CVE-2018-19461Jun 7, 2019
    risk 0.00cvss epss 0.00

    admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.

  • CVE-2018-19462Jun 7, 2019
    risk 0.00cvss epss 0.00

    admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.

  • CVE-2019-12362May 27, 2019
    risk 0.00cvss epss 0.00

    EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.

  • CVE-2019-12361May 27, 2019
    risk 0.00cvss epss 0.00

    EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.

  • CVE-2018-18449Mar 7, 2019
    risk 0.00cvss epss 0.00

    EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.

  • CVE-2018-20300Dec 20, 2018
    risk 0.00cvss epss 0.01

    Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.

  • CVE-2018-18869Oct 31, 2018
    risk 0.00cvss epss 0.04

    EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.

  • CVE-2018-18086Oct 9, 2018
    risk 0.00cvss epss 0.00

    EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.

  • CVE-2018-6880Feb 12, 2018
    risk 0.00cvss epss 0.00

    EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.

  • CVE-2018-6881Feb 12, 2018
    risk 0.00cvss epss 0.00

    EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.