philippe/FrogCMS

philippe/FrogCMS

Releases0
Stars160
Frog CMS simplifies content management by offering an elegant user interface, flexible templating per page, simple user management and permissions, as well as the tools necessary for file management.

CVE History

CVEPublishedCVSS v3CVSS v2
4.9 MEDIUM4 MEDIUM

A vulnerability exists within the FileManagerController.php function in FrogCMS 0.9.5 which allows an attacker to perform a directory traversal attack via a GET request urlencode parameter.

9.8 CRITICAL7.5 HIGH

Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.

4.3 MEDIUM

admin/?/plugin/file_manager in Frog CMS 0.9.5 allows XSS by creating a new file containing a crafted attribute of an IMG element.

3.5 LOW

Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit/1 Body field.

5 MEDIUM

Frog CMS 0.9.5 provides a directory listing for a /public request.

6.5 MEDIUM

admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI.

3.5 LOW

Frog CMS 0.9.5 has XSS via the admin/?/layout/edit/1 Body field.

6.5 MEDIUM

Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.

6.5 MEDIUM

Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI.

3.5 LOW

Frog CMS 0.9.5 has XSS in the admin/?/page/edit/1 body field.

3.5 LOW

Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.

6.8 MEDIUM

Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.

3.5 LOW

Frog CMS 0.9.5 has stored XSS via /admin/?/plugin/comment/settings.

4 MEDIUM

Frog CMS 0.9.5 has an Upload vulnerability that can create files via /admin/?/plugin/file_manager/save.

6.5 MEDIUM

An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/upload URI, a similar issue to CVE-2014-4912.

3.5 LOW

An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/?/plugin/file_manager/rename URI. This can be used in conjunction with CSRF.

3.5 LOW

Frog CMS 0.9.5 has XSS in /install/index.php via the ['config']['admin_username'] field.

3.5 LOW

Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.

3.5 LOW

Frog CMS 0.9.5 has XSS via the admin/?/page/edit page[keywords] parameter, aka Edit Page Metadata.

3.5 LOW

Frog CMS 0.9.5 has XSS via the admin/?/layout/edit layout[name] parameter, aka Edit Layout.

3.5 LOW

Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit snippet[name] parameter, aka Edit Snippet.