Boonex
Boonex Dolphin: vulnerabilidades y CVE
Boonex Dolphin tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-27969 | Media (4.8) | 0.67% | — | 23 mar 2021 | Dolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter. |
| CVE-2013-3638 | Alta (8.8) | 1.4% | — | 6 feb 2020 | SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL commands via the 'pathes' parameter in 'categories.php'. |
| CVE-2014-4333 | Media (6.8) | 0.94% | — | 19 jun 2014 | Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection… |
| CVE-2014-3810 | Media (6.5) | 1.7% | — | 19 jun 2014 | SQL injection vulnerability in administration/profiles.php in BoonEx Dolphin 7.1.4 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the members[] parameter. NOTE: this can be… |
| CVE-2012-0873 | Media (4.3) | 4.3% | — | 23 feb 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) explain parameter to explanation.php or the (2) photos_only,… |
| CVE-2011-3728 | Media (5) | 1.2% | — | 23 sept 2011 | Dolphin 7.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xmlrpc/BxDolXMLRPCProfileView.php… |
| CVE-2008-3167 | Alta (9.3) | 6.5% | — | 14 jul 2008 | Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dir[plugins] parameter to (a)… |
| CVE-2006-5410 | Media (5.1) | 1.5% | — | 20 oct 2006 | PHP remote file inclusion vulnerability in templates/tmpl_dfl/scripts/index.php in BoonEx Dolphin 5.2 allows remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter. NOTE: it is possible that… |
| CVE-2006-4189 | Media (5.1) | 6.3% | — | 17 ago 2006 | Multiple PHP remote file inclusion vulnerabilities in Dolphin 5.1 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) index.php, (2) aemodule.php, (3) browse.php, (4) cc.php,… |