CVE-2024-44871
- EPSS 19.62%
- Veröffentlicht 10.09.2024 17:15:37
- Zuletzt bearbeitet 13.09.2024 15:28:21
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-44872
- EPSS 0.18%
- Veröffentlicht 10.09.2024 17:15:37
- Zuletzt bearbeitet 13.09.2024 15:26:12
A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
CVE-2024-29368
- EPSS 0.12%
- Veröffentlicht 22.04.2024 21:15:49
- Zuletzt bearbeitet 30.04.2025 16:45:39
An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file execution or storage of malicious content.
CVE-2024-2245
- EPSS 0.2%
- Veröffentlicht 07.03.2024 13:15:07
- Zuletzt bearbeitet 04.03.2025 12:24:40
Cross-Site Scripting vulnerability in moziloCMS version 2.0. By sending a POST request to the '/install.php' endpoint, a JavaScript payload could be executed in the 'username' parameter.
CVE-2022-23357
- EPSS 1.46%
- Veröffentlicht 03.02.2022 03:15:06
- Zuletzt bearbeitet 21.11.2024 06:48:27
mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.
CVE-2020-25394
- EPSS 0.35%
- Veröffentlicht 09.07.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 05:17:56
A stored cross site scripting (XSS) vulnerability in moziloCMS 2.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Content" parameter.
CVE-2009-4209
- EPSS 0.2%
- Veröffentlicht 04.12.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) file parameters in an editsite action, different vectors than CVE-2008-61...
CVE-2009-1367
- EPSS 2.65%
- Veröffentlicht 22.04.2009 21:30:14
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in index.php in moziloCMS 1.11 allows remote attackers to inject arbitrary web script or HTML via the query parameter in search action, a different issue than CVE-2008-6127.2a.
CVE-2009-1368
- EPSS 2.71%
- Veröffentlicht 22.04.2009 21:30:14
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. NOTE: this might be the same issue as CVE-2008-6126.2, which may have been fixed in 1.10.3.
- EPSS 5.01%
- Veröffentlicht 22.04.2009 21:30:14
- Zuletzt bearbeitet 09.04.2025 00:30:58
moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter to index.php, or (4) file[] parameter to download.php, which reveals the installation path in an err...