HamayeshNegar
Products
1- 20 CVEs
Recent CVEs
20| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-18982 | 0.08 | — | 0.67 | Nov 27, 2018 | NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution. | |||
| CVE-2018-17936 | 0.08 | — | 0.67 | Nov 27, 2018 | NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote code execution. | |||
| CVE-2018-17934 | 0.08 | — | 0.68 | Nov 27, 2018 | NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user, obtain restricted information, or execute arbitrary code. | |||
| CVE-2018-17832 | 0.03 | — | 0.00 | Oct 1, 2018 | XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter. | |||
| CVE-2018-12094 | 0.03 | — | 0.00 | Jun 11, 2018 | Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |||
| CVE-2018-10313 | 0.03 | — | 0.00 | Apr 24, 2018 | WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI. | |||
| CVE-2018-9926 | 0.03 | — | 0.00 | Apr 10, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add. | |||
| CVE-2019-20390 | 0.00 | — | 0.00 | May 15, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit an attacker's web page. The application fails to validate… | |||
| CVE-2018-19414 | 0.00 | — | 0.02 | Jan 3, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to groups.php; (2) username parameter to login.php; or (3) date parameter to search.php. | |||
| CVE-2018-20064 | 0.00 | — | 0.00 | Dec 11, 2018 | doorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a dg-user/?controller=theme&action=edit&name=doorgets&file=../../1.txt%00 URI with content in the theme_content_nofi parameter. | |||
| CVE-2018-16629 | 0.00 | — | 0.00 | Dec 4, 2018 | panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. | |||
| CVE-2018-18938 | 0.00 | — | 0.00 | Nov 5, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field. | |||
| CVE-2018-17852 | 0.00 | — | 0.00 | Oct 1, 2018 | A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the /index.php?m=coupon&f=card&v=detail_listing URI. | |||
| CVE-2018-16975 | 0.00 | — | 0.01 | Sep 12, 2018 | An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input validation in… | |||
| CVE-2018-16775 | 0.00 | — | 0.00 | Sep 10, 2018 | An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu. | |||
| CVE-2018-16350 | 0.00 | — | 0.00 | Sep 2, 2018 | WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter. | |||
| CVE-2018-12984 | 0.00 | — | 0.03 | Jun 29, 2018 | Hycus CMS 1.0.4 allows Authentication Bypass via "'=' 'OR'" credentials. | |||
| CVE-2018-6518 | 0.00 | — | 0.00 | Apr 26, 2018 | Composr CMS 10.0.13 has XSS via the site_name parameter in a page=admin-setupwizard&type=step3 request to /adminzone/index.php. | |||
| CVE-2017-17902 | 0.00 | — | 0.00 | Apr 22, 2018 | SQL Injection exists in Kliqqi CMS 3.5.2 via the randkey parameter of a new story at the pligg/story.php?title= URI. | |||
| CVE-2017-18194 | 0.00 | — | 0.01 | Feb 22, 2018 | SQL injection vulnerability in users/signup.php in the "signup" component in HamayeshNegar CMS allows a remote attacker to execute arbitrary SQL commands via the "utype" parameter. |
- CVE-2018-18982Nov 27, 2018risk 0.08cvss —epss 0.67
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.
- CVE-2018-17936Nov 27, 2018risk 0.08cvss —epss 0.67
NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote code execution.
- CVE-2018-17934Nov 27, 2018risk 0.08cvss —epss 0.68
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user, obtain restricted information, or execute arbitrary code.
- CVE-2018-17832Oct 1, 2018risk 0.03cvss —epss 0.00
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
- CVE-2018-12094Jun 11, 2018risk 0.03cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
- CVE-2018-10313Apr 24, 2018risk 0.03cvss —epss 0.00
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.
- CVE-2018-9926Apr 10, 2018risk 0.03cvss —epss 0.00
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add.
- CVE-2019-20390May 15, 2020risk 0.00cvss —epss 0.00
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit an attacker's web page. The application fails to validate…
- CVE-2018-19414Jan 3, 2019risk 0.00cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to groups.php; (2) username parameter to login.php; or (3) date parameter to search.php.
- CVE-2018-20064Dec 11, 2018risk 0.00cvss —epss 0.00
doorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a dg-user/?controller=theme&action=edit&name=doorgets&file=../../1.txt%00 URI with content in the theme_content_nofi parameter.
- CVE-2018-16629Dec 4, 2018risk 0.00cvss —epss 0.00
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
- CVE-2018-18938Nov 5, 2018risk 0.00cvss —epss 0.00
An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field.
- CVE-2018-17852Oct 1, 2018risk 0.00cvss —epss 0.00
A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the /index.php?m=coupon&f=card&v=detail_listing URI.
- CVE-2018-16975Sep 12, 2018risk 0.00cvss —epss 0.01
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input validation in…
- CVE-2018-16775Sep 10, 2018risk 0.00cvss —epss 0.00
An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu.
- CVE-2018-16350Sep 2, 2018risk 0.00cvss —epss 0.00
WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter.
- CVE-2018-12984Jun 29, 2018risk 0.00cvss —epss 0.03
Hycus CMS 1.0.4 allows Authentication Bypass via "'=' 'OR'" credentials.
- CVE-2018-6518Apr 26, 2018risk 0.00cvss —epss 0.00
Composr CMS 10.0.13 has XSS via the site_name parameter in a page=admin-setupwizard&type=step3 request to /adminzone/index.php.
- CVE-2017-17902Apr 22, 2018risk 0.00cvss —epss 0.00
SQL Injection exists in Kliqqi CMS 3.5.2 via the randkey parameter of a new story at the pligg/story.php?title= URI.
- CVE-2017-18194Feb 22, 2018risk 0.00cvss —epss 0.01
SQL injection vulnerability in users/signup.php in the "signup" component in HamayeshNegar CMS allows a remote attacker to execute arbitrary SQL commands via the "utype" parameter.