Skip to content
Noroxi

bigtreecms records

45 published records for vendor bigtreecms.

All records

45 records
  • site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the B

    CriticalCVSS 9.8No exploitEPSS 2%

    bigtreecms · bigtree cmsApr 30, 2018

  • Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety ch

    CriticalCVSS 9.8No exploitEPSS 2%

    bigtreecms · bigtree cmsApr 11, 2017

  • CVE-2017-9364
    39Monitor

    Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a

    CriticalCVSS 9.8No exploitEPSS 1%

    bigtreecms · bigtree cmsJun 2, 2017

  • CVE-2017-9442
    36Monitor

    BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web s

    HighCVSS 8.8No exploitEPSS 2%

    bigtreecms · bigtree cmsJun 5, 2017

  • A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands t

    HighCVSS 8.8No exploitEPSS 2%

    bigtreecms · bigtree cmsJun 1, 2021

  • CVE-2017-9427
    35Monitor

    SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin

    HighCVSS 8.8No exploitEPSS 2%

    bigtreecms · bigtree cmsJun 4, 2017

  • A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attac

    HighCVSS 8.8No exploitEPSS 1%

    bigtreecms · bigtree cmsJun 1, 2021

  • CVE-2017-9443
    35Monitor

    BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json i

    HighCVSS 8.8No exploitEPSS 1%

    bigtreecms · bigtree cmsJun 5, 2017

  • CVE-2017-9449
    35Monitor

    SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin

    HighCVSS 8.8No exploitEPSS 1%

    bigtreecms · bigtree cmsJun 6, 2017

  • SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbi

    HighCVSS 8.8No exploitEPSS 1%

    bigtreecms · bigtree cmsJul 29, 2017

  • CVE-2017-7881
    35Monitor

    BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing th

    HighCVSS 8.8No exploitEPSS 1%

    bigtreecms · bigtree cmsApr 15, 2017

  • CVE-2017-9365
    35Monitor

    CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?fo

    HighCVSS 8.8No exploitEPSS 0%

    bigtreecms · bigtree cmsJun 2, 2017

  • CVE-2017-9379
    35Monitor

    Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.p

    HighCVSS 8.8No exploitEPSS 0%

    bigtreecms · bigtree cmsJun 2, 2017

  • CVE-2017-9444
    35Monitor

    BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.p

    HighCVSS 8.8No exploitEPSS 0%

    bigtreecms · bigtree cmsJun 5, 2017

  • BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ su

    HighCVSS 8.1No exploitEPSS 2%

    bigtreecms · bigtree cmsSep 23, 2018

  • CVE-2013-4879
    31Monitor

    SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL

    HighCVSS 7.5Proof of conceptEPSS 2%

    bigtreecms · bigtree cmsAug 14, 2013

  • BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-

    HighCVSS 7.5No exploitEPSS 2%

    bigtreecms · bigtree cmsSep 13, 2018

  • CVE-2017-9428
    31Monitor

    A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows

    HighCVSS 7.5No exploitEPSS 2%

    bigtreecms · bigtree cmsJun 4, 2017

  • CVE-2013-4881
    28Monitor

    Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote atta

    MediumCVSS 6.8Proof of conceptEPSS 2%

    bigtreecms · bigtree cmsAug 19, 2013

  • CVE-2017-6914
    28Monitor

    CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page.

    HighCVSS 7.1No exploitEPSS 0%

    bigtreecms · bigtree cmsMar 15, 2017

  • CVE-2013-5313
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote atta

    MediumCVSS 6.8No exploitEPSS 1%

    bigtreecms · bigtree cmsAug 19, 2013

  • A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain inf

    MediumCVSS 6.5No exploitEPSS 1%

    bigtreecms · bigtree cmsNov 27, 2017

  • CVE-2017-9378
    26Monitor

    BigTree CMS through 4.2.18 does not prevent a user from deleting their own account.

    MediumCVSS 6.5No exploitEPSS 1%

    bigtreecms · bigtree cmsJun 2, 2017

  • In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload a

    MediumCVSS 6.1Proof of conceptEPSS 4%

    bigtreecms · bigtree cmsOct 16, 2018

  • BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vu

    MediumCVSS 6.1No exploitEPSS 1%

    bigtreecms · bigtree cmsJun 26, 2018