Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
auracms vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2014-3975
Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote malicious users to list a directory via a full pathname in the viewdir parameter.
Auracms Auracms 3.0
1 EDB exploit
6.8
CVSSv2
CVE-2018-16338
An issue exists in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subsequently add a page or menu, or submit a topic.
Auracms Auracms 2.3
7.5
CVSSv2
CVE-2007-4804
Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote malicious users to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171. NOTE: the scripts may ...
Auracms Auracms 1.5 Rc
1 EDB exploit
7.5
CVSSv2
CVE-2007-4905
Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote malicious users to upload and execute arbitrary PHP files via the image parameter, which places a file under files/.
Auracms Auracms 2.1
1 EDB exploit
3.5
CVSSv2
CVE-2018-15199
AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.
Auracms Auracms 2.3
10
CVSSv2
CVE-2008-0735
SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote malicious users to execute arbitrary SQL commands via the albums parameter.
Auracms Auracms 2.2
1 EDB exploit
7.5
CVSSv2
CVE-2008-0811
Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote malicious users to execute arbitrary SQL commands via (1) the kid parameter to (a) mod/dl.php or (b) mod/links.php, and (2) the query parameter to search.php.
Auracms Auracms 1.62
1 EDB exploit
4.3
CVSSv2
CVE-2006-3558
Multiple cross-site scripting (XSS) vulnerabilities in Arif Supriyanto auraCMS 1.62 allow remote malicious users to inject arbitrary web script or HTML via (1) the judul_artikel parameter in teman.php and (2) the title of an article sent to admin, which is displayed when unauthen...
Arif Supriyanto Auracms 1.62
7.5
CVSSv2
CVE-2006-3559
Multiple SQL injection vulnerabilities in Arif Supriyanto auraCMS 1.62 allow remote malicious users to execute arbitrary SQL commands and delete all shoutbox messages via the (1) name and (2) pesan parameters.
Arif Supriyanto Auracms 1.62
7.5
CVSSv2
CVE-2007-4171
SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote malicious users to execute arbitrary SQL commands via the id parameter to the default URI. NOTE: some of these details are obtained from third party information.
Auracms Modul Forum Sederhana
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
firmware
CVE-2023-52866
CVE-2024-4367
CVE-2024-1721
CVE-2023-34992
XML injection
CVE-2023-52817
SQL
CVE-2023-52855
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »