Publiccms

Publiccms

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.26%
  • Veröffentlicht 09.07.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 05:12:31

Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 04.11.2018 05:29:00
  • Zuletzt bearbeitet 21.11.2024 03:56:53

An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typically has 'class="icon-globe icon-large"' in its value), as demonstrated by an 'UPDATE sys_module SET attached = "[XSS]" WHERE id="pag...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 23.09.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:54:16

An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is valid, which makes it easier to conduct brute-force attacks.

Exploit
  • EPSS 2.37%
  • Veröffentlicht 27.06.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:05

A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 15.06.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:45:19

An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsTemplate/content.html?path=../ URI.

Exploit
  • EPSS 0.54%
  • Veröffentlicht 15.06.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:45:19

An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsWebFile/list.html?path=../ URI.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 26.05.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:29

An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin account.