CVE-2025-41033
- EPSS 0.04%
- Published 04.09.2025 11:06:38
- Last modified 04.09.2025 18:45:25
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5BPage%5D%5Bname%5D' parameter in /apprain/page/manage-dynamic-pages/cre...
CVE-2025-41032
- EPSS 0.04%
- Published 04.09.2025 11:06:27
- Last modified 04.09.2025 18:45:32
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5BAdmin%5D%5Busername%5D' parameter in /apprain/admin/manage/add/.
CVE-2013-6058
- EPSS 4.61%
- Published 14.11.2013 20:55:04
- Last modified 11.04.2025 00:51:21
SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to blog-by-cat/.
CVE-2011-5229
- EPSS 1.14%
- Published 25.10.2012 17:55:06
- Last modified 11.04.2025 00:51:21
SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.
CVE-2011-5228
- EPSS 4.67%
- Published 25.10.2012 17:55:06
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to inject arbitrary web script or HTML via the ss parameter.
CVE-2012-1153
- EPSS 79.54%
- Published 06.10.2012 21:55:03
- Last modified 11.04.2025 00:51:21
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to th...
- EPSS 0.28%
- Published 23.09.2011 23:55:02
- Last modified 11.04.2025 00:51:21
appRain 0.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by cron.php.