Bigtreecms

Bigtree Cms

44 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 06.06.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in core\admin\ajax\pages\save-revision.php and core\admi...

  • EPSS 0.34%
  • Veröffentlicht 06.06.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/modules/views/create.php. The attacker creates a crafted table name at admin/developer/modu...

  • EPSS 0.11%
  • Veröffentlicht 05.06.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the index.php/admin/developer/upgrade/ignore/?versi...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 05.06.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in core\admin\modules\developer\extensions\install\process.php and co...

Exploit
  • EPSS 2.26%
  • Veröffentlicht 05.06.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename patterns such as cache/package/xxx/yyy.php. This issu...

  • EPSS 0.19%
  • Veröffentlicht 05.06.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mishandling of the (1) title or (2) version or (3) au...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 04.06.2017 23:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows, allowing attackers to read arbitrary files via ..\ sequences in the directory parameter.

Exploit
  • EPSS 0.35%
  • Veröffentlicht 04.06.2017 23:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin\modules\developer\modules\designer\form-create.php. The attacker creates a crafted table name at admin/develo...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 02.06.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.php and the from or to parameter to core\admin\modules\dashboard\vitals-statistics\404\create-301.php.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 02.06.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such as data backups) to complete bef...