CVE-2020-24139
- EPSS 0.3%
- Veröffentlicht 07.04.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:14:25
Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerable web application via the path parameter to wex/cssjs.php. It can help identify open ports, local network hosts and execute comman...
CVE-2020-24137
- EPSS 0.15%
- Veröffentlicht 07.04.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:14:25
Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the path parameter to wex/cssjs.php.
CVE-2020-24135
- EPSS 0.28%
- Veröffentlicht 07.04.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:14:24
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Wcms 0.3.2, which allows remote attackers to inject arbitrary web script and HTML via the type parameter to wex/cssjs.php.
CVE-2020-24138
- EPSS 0.28%
- Veröffentlicht 07.04.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:14:25
Cross Site Scripting (XSS) vulnerability in wcms 0.3.2 allows remote attackers to inject arbitrary web script and HTML via the pagename parameter to wex/html.php.
CVE-2020-24136
- EPSS 1.28%
- Veröffentlicht 07.04.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:14:24
Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename parameter to wex/html.php.
CVE-2019-14240
- EPSS 0.33%
- Veröffentlicht 23.07.2019 12:15:11
- Zuletzt bearbeitet 21.11.2024 04:26:16
WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html URI.
CVE-2019-11377
- EPSS 0.4%
- Veröffentlicht 20.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:59
wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension according to the fm_get_text_exts function.