Icmsdev
Icmsdev Icms: vulnerabilidades y CVE
Icmsdev Icms tiene 18 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses0
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-42322 | Crítica (9.8) | 0.86% | — | 20 sept 2023 | Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information. |
| CVE-2023-42321 | Alta (8.8) | 0.41% | — | 20 sept 2023 | Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files. |
| CVE-2019-14976 | Media (6.1) | 0.83% | — | 12 ago 2019 | iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter. |
| CVE-2019-6259 | Crítica (9.8) | 1.5% | — | 14 ene 2019 | An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id parameter. |
| CVE-2018-18702 | Crítica (9.8) | 1.5% | — | 29 oct 2018 | spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion. |
| CVE-2018-16314 | Alta (8.8) | 0.66% | — | 1 sept 2018 | An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exist, only the Referer header is validated, which can be bypassed via an admincp.php substring in this… |
| CVE-2018-15895 | Alta (7.5) | 1.5% | — | 27 ago 2018 | An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS hostnames associated with private and reserved IP addresses, as… |
| CVE-2018-14858 | Alta (7.5) | 1.5% | — | 2 ago 2018 | An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_tools.class.php does not block private and reserved IP addresses such as 10.0.0.0/8. NOTE: this… |
| CVE-2018-14514 | Crítica (9.8) | 1.6% | — | 23 jul 2018 | An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have unspecified other impact. |
| CVE-2018-14415 | Media (6.1) | 0.83% | — | 20 jul 2018 | An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen. |
| CVE-2018-12498 | Crítica (9.8) | 1.5% | — | 15 jun 2018 | spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php. |
| CVE-2018-10250 | Media (5.4) | 0.61% | — | 20 abr 2018 | iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search. |
| CVE-2018-10222 | Alta (8.8) | 0.59% | — | 19 abr 2018 | An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?app=article_category&do=save&frame=iPHP. |
| CVE-2018-10117 | Alta (8.8) | 0.53% | — | 16 abr 2018 | An issue was discovered in idreamsoft iCMS V7.0.7. There is a CSRF vulnerability that can add an admin account via admincp.php?app=members&do=save&frame=iPHP. |
| CVE-2018-9925 | Media (5.4) | 0.62% | — | 10 abr 2018 | An issue was discovered in idreamsoft iCMS through 7.0.7. XSS exists via the nickname field in an admincp.php?app=user&do=save&frame=iPHP request. |
| CVE-2018-9924 | Crítica (9.8) | 1.4% | — | 10 abr 2018 | An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp.php?app=tag&do=save&frame=iPHP request. |
| CVE-2018-9923 | Alta (8.8) | 0.60% | — | 10 abr 2018 | An issue was discovered in idreamsoft iCMS through 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an article via an app=article&do=save&frame=iPHP request. |
| CVE-2018-9922 | Media (5.3) | 1.1% | — | 10 abr 2018 | An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weixin.class.php pathname. |