Search Results (Refine Search)
- CPE Product Version: cpe:/a:frog_cms_project:frog_cms:0.9.5
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2018-20778 |
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows XSS by creating a new file containing a crafted attribute of an IMG element. Published: February 10, 2019; 9:29:01 PM -0500 |
V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20777 |
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit/1 Body field. Published: February 10, 2019; 9:29:01 PM -0500 |
V3.0: 5.4 MEDIUM V2.0: 3.5 LOW |
CVE-2018-20776 |
Frog CMS 0.9.5 provides a directory listing for a /public request. Published: February 10, 2019; 9:29:01 PM -0500 |
V3.0: 7.5 HIGH V2.0: 5.0 MEDIUM |
CVE-2018-20775 |
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI. Published: February 10, 2019; 9:29:01 PM -0500 |
V3.0: 7.2 HIGH V2.0: 6.5 MEDIUM |
CVE-2018-20774 |
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit/1 Body field. Published: February 10, 2019; 9:29:01 PM -0500 |
V3.0: 5.4 MEDIUM V2.0: 3.5 LOW |
CVE-2018-20773 |
Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines. Published: February 10, 2019; 9:29:00 PM -0500 |
V3.0: 7.2 HIGH V2.0: 6.5 MEDIUM |
CVE-2018-20772 |
Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI. Published: February 10, 2019; 9:29:00 PM -0500 |
V3.0: 7.2 HIGH V2.0: 6.5 MEDIUM |
CVE-2019-6243 |
Frog CMS 0.9.5 allows XSS via the forgot password page (aka the /admin/?/login/forgot URI). Published: January 11, 2019; 9:29:00 PM -0500 |
V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20680 |
Frog CMS 0.9.5 has XSS in the admin/?/page/edit/1 body field. Published: January 09, 2019; 12:29:00 PM -0500 |
V3.0: 4.8 MEDIUM V2.0: 3.5 LOW |
CVE-2018-20448 |
Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI. Published: December 25, 2018; 11:29:00 AM -0500 |
V3.0: 5.4 MEDIUM V2.0: 3.5 LOW |
CVE-2018-16374 |
Frog CMS 0.9.5 has stored XSS via /admin/?/plugin/comment/settings. Published: September 02, 2018; 8:29:00 PM -0400 |
V3.0: 4.8 MEDIUM V2.0: 3.5 LOW |
CVE-2018-16373 |
Frog CMS 0.9.5 has an Upload vulnerability that can create files via /admin/?/plugin/file_manager/save. Published: September 02, 2018; 8:29:00 PM -0400 |
V3.0: 4.9 MEDIUM V2.0: 4.0 MEDIUM |
CVE-2018-11098 |
An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/upload URI, a similar issue to CVE-2014-4912. Published: May 14, 2018; 9:29:00 PM -0400 |
V3.0: 7.2 HIGH V2.0: 6.5 MEDIUM |
CVE-2018-9992 |
Frog CMS 0.9.5 has XSS via the name field of a new "File" or "Directory" on the admin/?/plugin/file_manager/browse/ screen. Published: April 11, 2018; 2:29:00 AM -0400 |
V3.0: 4.8 MEDIUM V2.0: 3.5 LOW |
CVE-2018-9991 |
Frog CMS 0.9.5 has XSS via the /admin/?/user/add Name or Username parameter. Published: April 11, 2018; 2:29:00 AM -0400 |
V3.0: 4.8 MEDIUM V2.0: 3.5 LOW |
CVE-2018-8908 |
An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges. This happens due to lack of an anti-CSRF token in state modification requests. Published: March 31, 2018; 6:29:00 PM -0400 |
V3.0: 8.8 HIGH V2.0: 6.8 MEDIUM |
CVE-2014-4912 |
An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation. Published: March 22, 2018; 12:29:00 AM -0400 |
V3.0: 9.8 CRITICAL V2.0: 7.5 HIGH |