RSS   Vulnerabilities for 'Cmsimple'   RSS

2022-04-13
 
CVE-2021-43741

CWE-22
 

 
CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution.

 
2018-12-19
 
CVE-2018-19508

CWE-79
 

 
CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI.

 
 
CVE-2018-19507

CWE-79
 

 
CMSimple 4.7.5 has XSS via an admin's use of a ?file=config&action=array URI.

 
2008-06-10
 
CVE-2008-2650

CWE-22
 

 
Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sl parameter to index.php. NOTE: this can be leveraged for remote file execution by including adm.php and then invoking the upload action. NOTE: on 20080601, the vendor patched 3.1 without changing the version number.

 

 >>> Vendor: Cmsimple 2 Products
Cmsimple
Cmsimple classic


Copyright 2024, cxsecurity.com

 

Back to Top