Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
auracms vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-0811
Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote malicious users to execute arbitrary SQL commands via (1) the kid parameter to (a) mod/dl.php or (b) mod/links.php, and (2) the query parameter to search.php.
Auracms Auracms 1.62
1 EDB exploit
NA
CVE-2014-3975
Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote malicious users to list a directory via a full pathname in the viewdir parameter.
Auracms Auracms 3.0
1 EDB exploit
NA
CVE-2007-6552
Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the act parameter, possibly involving the news pilih component; as demonstrated by including admin/admin_users.php to...
Auracms Auracms 2.2
1 EDB exploit
8.8
CVSSv3
CVE-2018-16338
An issue exists in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subsequently add a page or menu, or submit a topic.
Auracms Auracms 2.3
NA
CVE-2010-4774
SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote malicious users to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-4804 and CVE-2007-4171.
Auracms Auracms 1.62
1 EDB exploit
NA
CVE-2007-4804
Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote malicious users to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171. NOTE: the scripts may ...
Auracms Auracms 1.5 Rc
1 EDB exploit
NA
CVE-2007-4905
Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote malicious users to upload and execute arbitrary PHP files via the image parameter, which places a file under files/.
Auracms Auracms 2.1
1 EDB exploit
NA
CVE-2006-3559
Multiple SQL injection vulnerabilities in Arif Supriyanto auraCMS 1.62 allow remote malicious users to execute arbitrary SQL commands and delete all shoutbox messages via the (1) name and (2) pesan parameters.
Arif Supriyanto Auracms 1.62
NA
CVE-2006-3558
Multiple cross-site scripting (XSS) vulnerabilities in Arif Supriyanto auraCMS 1.62 allow remote malicious users to inject arbitrary web script or HTML via (1) the judul_artikel parameter in teman.php and (2) the title of an article sent to admin, which is displayed when unauthen...
Arif Supriyanto Auracms 1.62
NA
CVE-2005-0655
auraCMS 1.5 allows remote malicious users to obtain sensitive information via an HTTP request with an invalid id parameter to (1) teman.php, (2) hal.php, or (3) arsip.php, which reveals the path in a PHP error message.
Arif Supriyanto Auracms 1.5
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
cross-site request forgery
unauthorized
CVE-2024-33925
reflected XSS
CVE-2023-51580
CVE-2023-51579
CVE-2015-2051
CVE-2023-51609
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »