- EPSS 7.13%
- Veröffentlicht 03.08.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 08:09:25
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.
CVE-2019-16684
- EPSS 0.39%
- Veröffentlicht 30.09.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:30:58
An issue was discovered in the image-manager in Xoops 2.5.10. When any image with a JavaScript payload as its name is hovered over in the list or in the Edit page, the payload executes.
CVE-2019-16683
- EPSS 0.39%
- Veröffentlicht 30.09.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:30:58
An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered over while editing any image, a JavaScript payload executes.
CVE-2017-12139
- EPSS 0.23%
- Veröffentlicht 02.08.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php.
CVE-2017-12138
- EPSS 13.12%
- Veröffentlicht 02.08.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.
CVE-2017-11174
- EPSS 0.25%
- Veröffentlicht 12.07.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of GBK in CHARACTER SET and COLLATE clauses.
CVE-2017-7944
- EPSS 0.23%
- Veröffentlicht 24.04.2017 10:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in page_dbsettings.php.
CVE-2017-7290
- EPSS 0.64%
- Veröffentlicht 30.03.2017 07:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a back...
CVE-2014-8999
- EPSS 0.31%
- Veröffentlicht 20.11.2014 13:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS before 2.5.7 Final allows remote authenticated users to execute arbitrary SQL commands via the selgroups parameter.
CVE-2012-0984
- EPSS 20.63%
- Veröffentlicht 11.09.2014 14:16:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) to_userid parameter to modules/pm/pmlite.php or the (2) current_file, (3) imgcat_id, or (4) target par...