Home
Bugtraq
Full List
Only Bugs
Only Tricks
Only Exploits
Only Dorks
Only CVE
Only CWE
Fake Notes
Ranking
CVEMAP
Full List
Show Vendors
Show Products
CWE Dictionary
Check CVE Id
Check CWE Id
Search
Bugtraq
CVEMAP
By author
CVE Id
CWE Id
By vendors
By products
RSS
Bugtraq
CVEMAP
CVE Products
Bugs
Exploits
Dorks
More
cIFrex
Facebook
Twitter
Donate
About
Submit
Vulnerabilities for
'Victor cms'
2022-04-28
CVE-2022-28060
CWE-89
SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.
2022-04-21
CVE-2022-27478
CWE-434
Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin.
2022-03-04
CVE-2022-26201
CWE-89
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.
2022-02-03
CVE-2022-23873
CWE-89
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter.
2022-01-31
CVE-2021-46459
CWE-89
Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_user. These vulnerabilities can be exploited through a crafted POST request via the user_name, user_firstname,user_lastname, or user_email parameters.
CVE-2021-46458
CWE-89
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. This vulnerability can be exploited through a crafted POST request via the post_title parameter.
2021-07-23
CVE-2021-25203
CWE-434
Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.
2020-12-02
CVE-2020-29280
CWE-89
The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.
2020-10-27
CVE-2020-23945
CWE-89
A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database.
2020-07-07
CVE-2020-15599
CWE-79
Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
Copyright
2024
, cxsecurity.com
Back to Top