truonghuuphuc/CVE

truonghuuphuc/CVE

GitHubGitHub
Unavailable
This project is no longer available (or publicly accessible) from GitHub
Releases0
Stars3
All of my found cves

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.

5.4 MEDIUM3.5 LOW

In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=options" via the intro_title and intro_image parameters.

9.1 CRITICAL6.4 MEDIUM

mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.

5.4 MEDIUM3.5 LOW

Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitrary web scripts or HTML via a crafted payload insterted into the name, category, description parameters.

8.8 HIGH6.5 MEDIUM

Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter.

4.8 MEDIUM3.5 LOW

Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/configure.php via the parameter footer_info.

9.8 CRITICAL7.5 HIGH

Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.

7.5 HIGH7.8 HIGH

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

7.5 HIGH7.8 HIGH

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.

7.5 HIGH7.8 HIGH

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.

4.8 MEDIUM3.5 LOW

Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting (XSS) vulnerability, that allows attackers to inject arbitrary script via name parameters.