CVE-2016-9019
- EPSS 2.57%
- Veröffentlicht 07.03.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.
CVE-2016-7789
- EPSS 0.67%
- Veröffentlicht 07.03.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter.
CVE-2016-7788
- EPSS 0.58%
- Veröffentlicht 07.03.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2016-7784
- EPSS 0.58%
- Veröffentlicht 07.03.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.
CVE-2016-7783
- EPSS 0.49%
- Veröffentlicht 07.03.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.
CVE-2016-7782
- EPSS 0.49%
- Veröffentlicht 07.03.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the src parameter.
CVE-2016-7781
- EPSS 0.58%
- Veröffentlicht 07.03.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in framework/modules/blog/controllers/blogController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the author parameter.
CVE-2016-7780
- EPSS 0.58%
- Veröffentlicht 07.03.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in cron/find_help.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.
CVE-2016-7565
- EPSS 1.51%
- Veröffentlicht 13.02.2017 18:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
install/index.php in Exponent CMS 2.3.9 allows remote attackers to execute arbitrary commands via shell metacharacters in the sc array parameter.
CVE-2016-7400
- EPSS 19.42%
- Veröffentlicht 07.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an activate_address address controller action, (2) title parameter in a show blog controller acti...