İçeriğe atla
Noroxi

razorcms kayıtları

razorcms üreticisine ait 15 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

15 kayıt
  • CVE-2018-17986
    35İzleyin

    rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user.

    YüksekCVSS 8,8İstismar yokEPSS %1

    razorcms · razorcms4 Eki 2018

  • CVE-2009-1463
    30İzleyin

    Static code injection vulnerability in razorCMS before 0.4 allows remote attackers to inject arbitrary PHP code into any page by saving cont

    YüksekCVSS 7,5İstismar yokEPSS %2

    razorcms · razorcms28 Nis 2009

  • CVE-2012-1900
    28İzleyin

    Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authe

    OrtaCVSS 6,8Kavram kanıtıEPSS %3

    razorcms · razorcms22 Eki 2012

  • CVE-2009-1462
    28İzleyin

    The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsi

    YüksekCVSS 7,2İstismar yokEPSS %0

    razorcms · razorcms28 Nis 2009

  • CVE-2012-6038
    27İzleyin

    admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which a

    OrtaCVSS 6,5Kavram kanıtıEPSS %3

    razorcms · razorcms26 Kas 2012

  • CVE-2009-1459
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in razorCMS before 0.4 allows remote attackers to hijack the authentication of administrator

    OrtaCVSS 6,8İstismar yokEPSS %1

    razorcms · razorcms28 Nis 2009

  • CVE-2018-19905
    21İzleyin

    HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter.

    OrtaCVSS 5,4İstismar yokEPSS %1

    razorcms · razorcms31 Ara 2018

  • CVE-2018-19906
    21İzleyin

    Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter.

    OrtaCVSS 5,4İstismar yokEPSS %1

    razorcms · razorcms31 Ara 2018

  • CVE-2018-16727
    21İzleyin

    razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.

    OrtaCVSS 5,4İstismar yokEPSS %1

    razorcms · razorcms12 Eyl 2018

  • CVE-2018-16726
    21İzleyin

    razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.

    OrtaCVSS 5,4İstismar yokEPSS %1

    razorcms · razorcms12 Eyl 2018

  • CVE-2009-1458
    18İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web

    OrtaCVSS 4,3Kavram kanıtıEPSS %2

    razorcms · razorcms28 Nis 2009

  • CVE-2009-1460
    18İzleyin

    razorCMS before 0.4 uses weak permissions for (1) admin/core/admin_config.php, which allows local users to obtain the administrator's passwo

    OrtaCVSS 4,6İstismar yokEPSS %0

    razorcms · razorcms28 Nis 2009

  • CVE-2010-5051
    17İzleyin

    Cross-site scripting (XSS) vulnerability in admin/core/admin_func.php in razorCMS 1.0 stable allows remote attackers to inject arbitrary web

    OrtaCVSS 4,3Kavram kanıtıEPSS %2

    razorcms · razorcms22 Kas 2011

  • CVE-2012-5918
    16İzleyin

    razorCMS 1.2 allows remote authenticated users to access administrator directories and files by creating and deleting a directory.

    OrtaCVSS 4,0Kavram kanıtıEPSS %2

    razorcms · razorcms19 Kas 2012

  • CVE-2009-1461
    14İzleyin

    Cross-site scripting (XSS) vulnerability in the Create New Page form in razorCMS 0.3 RC2 and earlier allows remote authenticated users to in

    DüşükCVSS 3,5İstismar yokEPSS %1

    razorcms · razorcms28 Nis 2009