Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
auracms auracms 1.5 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-4908
Directory traversal vulnerability in index.php in AuraCMS 2.1 and previous versions allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the pilih parameter.
Auracms Auracms 1.5 Rc
Auracms Auracms 1.62
Auracms Auracms 1.0
Auracms Auracms 1.5
Auracms Auracms 2.0
Auracms Auracms 2.1
1 EDB exploit
NA
CVE-2007-4886
Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote malicious users to execute arbitrary PHP code via a (1) UNC share pathname, or a (2) ftp, (3) ftps, or (4) ssh2.sftp URL, in the pilih parameter, for which PHP remote file inclusion is b...
Auracms Auracms 1.1
Auracms Auracms 1.2
Auracms Auracms 2.1
Auracms Auracms 1.6 Beta
Auracms Auracms 1.61
Auracms Auracms 1.3
Auracms Auracms 1.5
Auracms Auracms 1.0
Auracms Auracms 1.62
Auracms Auracms 2.0
1 EDB exploit
NA
CVE-2014-1401
Multiple SQL injection vulnerabilities in AuraCMS 2.3 and previous versions allow remote authenticated users to execute arbitrary SQL commands via the (1) search parameter to mod/content/content.php or (2) CLIENT_IP, (3) X_FORWARDED_FOR, (4) X_FORWARDED, (5) FORWARDED_FOR, or (6)...
Auracms Auracms 2.2.2
Auracms Auracms 1.5
Auracms Auracms 2.1
Auracms Auracms 2.2
Auracms Auracms 2.2.1
Auracms Auracms 1.62
Auracms Auracms 2.0
Auracms Auracms 1.1
Auracms Auracms 1.0
Auracms Auracms
Auracms Auracms 1.61
Auracms Auracms 1.3
Auracms Auracms 1.2
1 EDB exploit
NA
CVE-2005-0655
auraCMS 1.5 allows remote malicious users to obtain sensitive information via an HTTP request with an invalid id parameter to (1) teman.php, (2) hal.php, or (3) arsip.php, which reveals the path in a PHP error message.
Arif Supriyanto Auracms 1.5
NA
CVE-2005-0656
Multiple cross-site scripting (XSS) vulnerabilities in auraCMS 1.5 allow remote malicious users to inject arbitrary web script or HTML via the (1) hits parameter to hits.php, (2) query parameter to index.php, or (3) theCount parameter to counter.php.
Arif Supriyanto Auracms 1.5
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
cross-site request forgery
unauthorized
CVE-2024-33925
reflected XSS
CVE-2023-51580
CVE-2023-51579
CVE-2015-2051
CVE-2023-51609
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started