Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpcms vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2005-1840
Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x prior to 1.2.1pl2 allows remote malicious users to read or include arbitrary files, as demonstrated using a .. (dot dot) in the language parameter to parser.php.
Phpcms Phpcms 1.2.1
Phpcms Phpcms 1.2.1 P12
Phpcms Phpcms 1.2.1 Pl1
Phpcms Phpcms 1.2.0
6.8
CVSSv2
CVE-2004-1202
Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and previous versions, with non-stealth and debug modes enabled, allows remote malicious users to inject arbitrary web script or HTML via the file parameter.
Phpcms Phpcms 1.1.9
Phpcms Phpcms 1.2
Phpcms Phpcms 1.2.1
5
CVSSv2
CVE-2004-1203
parser.php in phpCMS 1.2.1 and previous versions, with non-stealth and debug modes enabled, allows remote malicious users to gain sensitive information via an invalid file parameter, which reveals the web server's installation path.
Phpcms Phpcms 1.1.9
Phpcms Phpcms 1.2.0
Phpcms Phpcms 1.2.1
3.5
CVSSv2
CVE-2019-10027
PHPCMS 9.6.x up to and including 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.
Phpcms Phpcms
7.8
CVSSv2
CVE-2008-0513
Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote malicious users to read arbitrary files via a .. (dot dot) in the file parameter to parser/parser.php, as demonstrated by a filename ending with %00.gif, a different vector th...
Phpcms Phpcms 1.2.2
1 EDB exploit
7.5
CVSSv2
CVE-2006-3019
Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote malicious users to execute arbitrary PHP code via a URL in the PHPCMS_INCLUDEPATH parameter to files in parser/include/ including (1) class.parser_phpcms.php, (2) class.session_phpcms.php, (3) clas...
Phpcms Phpcms 1.2.1 P12
10 EDB exploits
7.5
CVSSv2
CVE-2018-19127
A code injection vulnerability in /type.php in PHPCMS 2008 allows malicious users to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template parameter, and is written to a data/cache_...
Phpcms Phpcms 2008
1 Github repository
7.5
CVSSv2
CVE-2020-22199
SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.
Phpcms Phpcms 2007
5
CVSSv2
CVE-2020-22200
Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.
Phpcms Phpcms 9.1.13
6.5
CVSSv2
CVE-2020-22201
phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.
Phpcms Phpcms 2008
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-3675
CVE-2024-3400
CVE-2024-23557
mass assignment
CVE-2023-1389
local file inclusion
CVE-2024-32596
file upload
CVE-2024-32593
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »