RSS   Vulnerabilities for 'Picoflat cms'   RSS

2007-11-09
 
CVE-2007-5920

CWE-22
 

 
index.php in Domenico Mancini PicoFlat CMS before 0.4.18 allows remote attackers to include certain files via unspecified vectors, possibly due to a directory traversal vulnerability. NOTE: this can be leveraged to bypass authentication and upload files by including pico_insert.php or unspecified other administrative scripts. NOTE: some of these details are obtained from third party information.

 
2007-10-12
 
CVE-2007-5390

 

 
PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pagina parameter.

 


Copyright 2024, cxsecurity.com

 

Back to Top