VYPR
Vendor

HamayeshNegar

Products
1
CVEs
20
Across products
20
Status
Private

Products

1

Recent CVEs

20
  • CVE-2018-18982Nov 27, 2018
    risk 0.08cvss epss 0.67

    NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.

  • CVE-2018-17936Nov 27, 2018
    risk 0.08cvss epss 0.67

    NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote code execution.

  • CVE-2018-17934Nov 27, 2018
    risk 0.08cvss epss 0.68

    NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user, obtain restricted information, or execute arbitrary code.

  • CVE-2018-17832Oct 1, 2018
    risk 0.03cvss epss 0.00

    XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.

  • CVE-2018-12094Jun 11, 2018
    risk 0.03cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

  • CVE-2018-10313Apr 24, 2018
    risk 0.03cvss epss 0.00

    WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.

  • CVE-2018-9926Apr 10, 2018
    risk 0.03cvss epss 0.00

    An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add.

  • CVE-2019-20390May 15, 2020
    risk 0.00cvss epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit an attacker's web page. The application fails to validate…

  • CVE-2018-19414Jan 3, 2019
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to groups.php; (2) username parameter to login.php; or (3) date parameter to search.php.

  • CVE-2018-20064Dec 11, 2018
    risk 0.00cvss epss 0.00

    doorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a dg-user/?controller=theme&action=edit&name=doorgets&file=../../1.txt%00 URI with content in the theme_content_nofi parameter.

  • CVE-2018-16629Dec 4, 2018
    risk 0.00cvss epss 0.00

    panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.

  • CVE-2018-18938Nov 5, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field.

  • CVE-2018-17852Oct 1, 2018
    risk 0.00cvss epss 0.00

    A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the /index.php?m=coupon&f=card&v=detail_listing URI.

  • CVE-2018-16975Sep 12, 2018
    risk 0.00cvss epss 0.01

    An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input validation in…

  • CVE-2018-16775Sep 10, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu.

  • CVE-2018-16350Sep 2, 2018
    risk 0.00cvss epss 0.00

    WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter.

  • CVE-2018-12984Jun 29, 2018
    risk 0.00cvss epss 0.03

    Hycus CMS 1.0.4 allows Authentication Bypass via "'=' 'OR'" credentials.

  • CVE-2018-6518Apr 26, 2018
    risk 0.00cvss epss 0.00

    Composr CMS 10.0.13 has XSS via the site_name parameter in a page=admin-setupwizard&type=step3 request to /adminzone/index.php.

  • CVE-2017-17902Apr 22, 2018
    risk 0.00cvss epss 0.00

    SQL Injection exists in Kliqqi CMS 3.5.2 via the randkey parameter of a new story at the pligg/story.php?title= URI.

  • CVE-2017-18194Feb 22, 2018
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in users/signup.php in the "signup" component in HamayeshNegar CMS allows a remote attacker to execute arbitrary SQL commands via the "utype" parameter.