CVE-2019-7236
- EPSS 1.03%
- Veröffentlicht 30.01.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:47:49
An issue was discovered in idreamsoft iCMS 7.0.13. editor/editor.admincp.php allows admincp.php?app=editor&do=fileManager dir=../ Directory Traversal.
CVE-2019-7235
- EPSS 0.46%
- Veröffentlicht 30.01.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:47:48
An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to designate an arbitrary directory because of an apps.admincp.php error. This directory can then be deleted via an admincp.php?a...
CVE-2019-7234
- EPSS 1.24%
- Veröffentlicht 30.01.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:47:48
An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to begin the process of creating a ZIP archive file with the complete contents of any directory because of an apps.admincp.php er...
CVE-2019-7160
- EPSS 1.07%
- Veröffentlicht 29.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:47:41
idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arbitrary PHP code from a ZIP file via the admincp.php?app=apps zipfile parameter to apps.admincp.php.
CVE-2018-16366
- EPSS 0.15%
- Veröffentlicht 02.09.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:36
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.
CVE-2018-16365
- EPSS 0.15%
- Veröffentlicht 02.09.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:36
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.
CVE-2018-16332
- EPSS 0.15%
- Veröffentlicht 02.09.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:32
An issue was discovered in iCMS 7.0.9. There is an admincp.php?app=article&do=update CSRF vulnerability.
CVE-2018-16320
- EPSS 0.85%
- Veröffentlicht 01.09.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:30
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file.
CVE-2018-13865
- EPSS 0.24%
- Veröffentlicht 10.07.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:12
An issue was discovered in idreamsoft iCMS 7.0.9. XSS exists via the callback parameter in a public/api.php uploadpic request, bypassing the iWAF protection mechanism.