CVE-2017-9448
- EPSS 0.14%
- Veröffentlicht 06.06.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in core\admin\ajax\pages\save-revision.php and core\admi...
CVE-2017-9449
- EPSS 0.34%
- Veröffentlicht 06.06.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/modules/views/create.php. The attacker creates a crafted table name at admin/developer/modu...
CVE-2017-9444
- EPSS 0.11%
- Veröffentlicht 05.06.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the index.php/admin/developer/upgrade/ignore/?versi...
CVE-2017-9443
- EPSS 0.55%
- Veröffentlicht 05.06.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in core\admin\modules\developer\extensions\install\process.php and co...
CVE-2017-9442
- EPSS 2.26%
- Veröffentlicht 05.06.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename patterns such as cache/package/xxx/yyy.php. This issu...
CVE-2017-9441
- EPSS 0.19%
- Veröffentlicht 05.06.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mishandling of the (1) title or (2) version or (3) au...
CVE-2017-9428
- EPSS 0.44%
- Veröffentlicht 04.06.2017 23:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows, allowing attackers to read arbitrary files via ..\ sequences in the directory parameter.
CVE-2017-9427
- EPSS 0.35%
- Veröffentlicht 04.06.2017 23:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin\modules\developer\modules\designer\form-create.php. The attacker creates a crafted table name at admin/develo...
CVE-2017-9379
- EPSS 0.11%
- Veröffentlicht 02.06.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.php and the from or to parameter to core\admin\modules\dashboard\vitals-statistics\404\create-301.php.
CVE-2017-9378
- EPSS 0.12%
- Veröffentlicht 02.06.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such as data backups) to complete bef...