CVE-2022-23880
- EPSS 1.62%
- Veröffentlicht 23.03.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:49:24
An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-25505
- EPSS 1.06%
- Veröffentlicht 21.03.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:52:17
Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.php.
CVE-2022-25578
- EPSS 1.75%
- Veröffentlicht 18.03.2022 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:52:23
taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
CVE-2022-23380
- EPSS 0.96%
- Veröffentlicht 01.03.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:29
There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit.
CVE-2021-44969
- EPSS 0.49%
- Veröffentlicht 10.02.2022 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:31:45
Taocms v3.0.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Management Column component.
CVE-2021-44983
- EPSS 1.11%
- Veröffentlicht 04.02.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:31:46
In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.
CVE-2022-23316
- EPSS 1%
- Veröffentlicht 04.02.2022 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:23
An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admin.php?action=file&ctrl=download&path=../../1.txt.
CVE-2021-46204
- EPSS 1.09%
- Veröffentlicht 19.01.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:45
Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulnerability via taocms\include\Model\Article.php.
CVE-2021-46203
- EPSS 1.06%
- Veröffentlicht 19.01.2022 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:33:45
Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter.
CVE-2021-45015
- EPSS 1.19%
- Veröffentlicht 14.12.2021 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:31:48
taocms 3.0.2 is vulnerable to arbitrary file deletion via taocms\include\Model\file.php from line 60 to line 72.