Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
icms vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2019-17552
An issue exists in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
Idreamsoft Icms 7.0.14
7.5
CVSSv3
CVE-2019-17583
idreamsoft iCMS 7.0.15 allows remote malicious users to cause a denial of service (resource consumption) via a query for many comments, as demonstrated by the admincp.php?app=comment&perpage= substring followed by a large positive integer.
Idreamsoft Icms 7.0.15
6.5
CVSSv3
CVE-2019-16677
An issue exists in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
Idreamsoft Icms 7.0.0
9.8
CVSSv3
CVE-2020-19142
iCMS 7 malicious users to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.
Idreamsoft Icms 7.0.0
8.8
CVSSv3
CVE-2020-26641
A Cross Site Request Forgery (CSRF) vulnerability exists in iCMS 7.0.16 which can allow an malicious user to execute arbitrary web scripts.
Idreamsoft Icms 7.0.16
9.8
CVSSv3
CVE-2020-19527
iCMS 7.0.14 malicious users to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.
Idreamsoft Icms 7.0.14
9.8
CVSSv3
CVE-2018-14514
An SSRF vulnerability exists in idreamsoft iCMS V7.0.9 that allows malicious users to read sensitive files, access an intranet, or possibly have unspecified other impact.
Icmsdev Icms 7.0.9
9.8
CVSSv3
CVE-2018-12498
spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php.
Icmsdev Icms 7.0.8
9.8
CVSSv3
CVE-2019-7160
idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arbitrary PHP code from a ZIP file via the admincp.php?app=apps zipfile parameter to apps.admincp.php.
Idreamsoft Icms 7.0.13
9.1
CVSSv3
CVE-2019-7234
An issue exists in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to begin the process of creating a ZIP archive file with the complete contents of any directory because of an apps.admincp.php error. This ZIP archive file can the...
Idreamsoft Icms 7.0.13
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »