CVE-2018-6550
- EPSS 0.21%
- Veröffentlicht 02.02.2018 09:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:53
Monstra CMS through 3.0.4 has XSS in the title function in plugins/box/pages/pages.plugin.php via a page title to admin/index.php.
CVE-2018-6383
- EPSS 12.73%
- Veröffentlicht 29.01.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:36
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated Admins or Editors to execute arbitrary PHP code by uploading a ...
CVE-2017-18048
- EPSS 77.01%
- Veröffentlicht 23.01.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:14
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.
- EPSS 0.35%
- Veröffentlicht 20.11.2014 13:55:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Monstra 3.0.1 and earlier uses a cookie to track how many login attempts have been attempted, which allows remote attackers to conduct brute force login attacks by deleting the login_attempts cookie or setting it to certain values.