Pbootcms

Pbootcms

40 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 19.12.2024 18:15:09
  • Zuletzt bearbeitet 06.01.2025 15:16:15

A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is some unknown functionality of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to pat...

  • EPSS 0.48%
  • Veröffentlicht 19.12.2024 17:15:08
  • Zuletzt bearbeitet 10.01.2025 21:42:42

A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to code injection. It is possible to ...

  • EPSS 0.19%
  • Veröffentlicht 28.10.2024 20:15:05
  • Zuletzt bearbeitet 17.04.2025 18:43:12

PbootCMS 3.2.8 is vulnerable to URL Redirect.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 29.01.2024 20:15:15
  • Zuletzt bearbeitet 21.11.2024 08:49:36

A vulnerability classified as problematic has been found in PbootCMS 3.2.5-20230421. Affected is an unknown function of the file /admin.php?p=/Area/index#tab=t2. The manipulation of the argument name leads to cross site scripting. It is possible to l...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 04.01.2024 08:15:08
  • Zuletzt bearbeitet 09.06.2025 18:15:23

Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform.

Exploit
  • EPSS 0.73%
  • Veröffentlicht 24.08.2023 18:15:07
  • Zuletzt bearbeitet 21.11.2024 08:15:58

PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.

Exploit
  • EPSS 0.86%
  • Veröffentlicht 03.02.2023 18:15:13
  • Zuletzt bearbeitet 04.04.2025 21:15:41

SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.

Exploit
  • EPSS 42.67%
  • Veröffentlicht 14.07.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 07:06:20

PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 02.06.2022 14:15:26
  • Zuletzt bearbeitet 21.11.2024 05:12:20

Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 12.08.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 05:08:36

Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php.