Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
icms vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2005-4396
Cross-site scripting (XSS) vulnerability in admin/Default.asp in iCMS allows remote malicious users to inject arbitrary web script or HTML via the LoginMSG parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources.
Icms Content Management Systems Icms
NA
CVE-2005-4397
SQL injection vulnerability in RunScript.asp iCMS allows remote malicious users to execute arbitrary SQL commands via the Event_ID parameter.
Icms Content Management Systems Icms
NA
CVE-2005-3574
PHP file inclusion vulnerability in index.php of iCMS allows remote malicious users to include arbitrary files via the page parameter.
Icms Content Management Systems Icms
7.5
CVSSv3
CVE-2018-15895
An SSRF vulnerability exists in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS hostnames associated with private and reserved IP addresses, as demonstrated by 127.0.0.1 in an A record. NOTE: this vulnerability exists bec...
Icmsdev Icms
7.5
CVSSv3
CVE-2018-14858
An SSRF vulnerability exists in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_tools.class.php does not block private and reserved IP addresses such as 10.0.0.0/8. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-14514.
Icmsdev Icms
5.3
CVSSv3
CVE-2018-9922
An issue exists in idreamsoft iCMS up to and including 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weixin.class.php pathname.
Icmsdev Icms
8.8
CVSSv3
CVE-2018-9923
An issue exists in idreamsoft iCMS up to and including 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an article via an app=article&do=save&frame=iPHP request.
Icmsdev Icms
9.8
CVSSv3
CVE-2018-9924
An issue exists in idreamsoft iCMS up to and including 7.0.7. SQL injection exists via the pid array parameter in an admincp.php?app=tag&do=save&frame=iPHP request.
Icmsdev Icms
5.4
CVSSv3
CVE-2018-9925
An issue exists in idreamsoft iCMS up to and including 7.0.7. XSS exists via the nickname field in an admincp.php?app=user&do=save&frame=iPHP request.
Icmsdev Icms
7.5
CVSSv3
CVE-2021-44977
In iCMS <=8.0.0, a directory traversal vulnerability allows an malicious user to read arbitrary files.
Idreamsoft Icms
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
hardcoded
arbitrary code
CVE-2024-2404
CVE-2024-21111
CVE-2024-28627
CVE-2024-4073
information disclosure
CVE-2024-32780
CVE-2024-4040
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »