Skip to content
Noroxi

Exponentcms records

60 published records for vendor exponentcms.

All records

60 records
  • Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.

    CriticalCVSS 9.8No exploitEPSS 7%

    exponentcms · exponent cmsJan 23, 2017

  • Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    exponentcms · exponent cmsFeb 7, 2017

  • Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php.

    CriticalCVSS 9.8No exploitEPSS 4%

    exponentcms · exponent cmsJan 12, 2017

  • Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php.

    CriticalCVSS 9.8No exploitEPSS 4%

    exponentcms · exponent cmsJan 12, 2017

  • SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent

    CriticalCVSS 9.8No exploitEPSS 3%

    exponentcms · exponent cmsMar 7, 2017

  • SQL injection vulnerability in framework/modules/help/controllers/helpController.php in Exponent CMS 2.3.9 and earlier allows remote attacke

    CriticalCVSS 9.8No exploitEPSS 3%

    exponentcms · exponent cmsMar 7, 2017

  • SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute

    CriticalCVSS 9.8No exploitEPSS 3%

    exponentcms · exponent cmsMar 7, 2017

  • SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbi

    CriticalCVSS 9.8No exploitEPSS 3%

    exponentcms · exponent cmsMar 7, 2017

  • SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbi

    CriticalCVSS 9.8No exploitEPSS 3%

    exponentcms · exponent cmsMar 7, 2017

  • SQL injection vulnerability in framework/modules/blog/controllers/blogController.php in Exponent CMS 2.3.9 and earlier allows remote attacke

    CriticalCVSS 9.8No exploitEPSS 3%

    exponentcms · exponent cmsMar 7, 2017

  • SQL injection vulnerability in cron/find_help.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL command

    CriticalCVSS 9.8No exploitEPSS 3%

    exponentcms · exponent cmsMar 7, 2017

  • SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows r

    CriticalCVSS 9.8No exploitEPSS 3%

    exponentcms · exponent cmsMar 7, 2017

  • SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbi

    CriticalCVSS 9.8No exploitEPSS 2%

    exponentcms · exponent cmsMar 7, 2017

  • Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprote

    CriticalCVSS 9.8No exploitEPSS 2%

    exponentcms · exponent cmsNov 3, 2016

  • install/index.php in Exponent CMS 2.3.9 allows remote attackers to execute arbitrary commands via shell metacharacters in the sc array param

    CriticalCVSS 9.8No exploitEPSS 2%

    exponentcms · exponent cmsFeb 13, 2017

  • SQL injection vulnerability in framework/modules/filedownloads/controllers/filedownloadController.php in Exponent CMS 2.3.9 and earlier allo

    CriticalCVSS 9.8No exploitEPSS 2%

    exponentcms · exponent cmsMar 7, 2017

  • Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong locatio

    CriticalCVSS 9.8No exploitEPSS 2%

    exponentcms · exponent cmsMar 6, 2018

  • Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related

    CriticalCVSS 9.8No exploitEPSS 2%

    exponentcms · exponent cmsMay 23, 2019

  • Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related

    CriticalCVSS 9.8No exploitEPSS 2%

    exponentcms · exponent cmsMay 24, 2019

  • Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules

    CriticalCVSS 9.8No exploitEPSS 2%

    exponentcms · exponent cmsApr 21, 2017

  • An issue was discovered in Exponent CMS 2.4.1.

    CriticalCVSS 9.8No exploitEPSS 2%

    exponentcms · exponent cmsFeb 6, 2017

  • Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.

    CriticalCVSS 9.8No exploitEPSS 2%

    exponentcms · exponent cmsMay 23, 2019

  • Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.

    CriticalCVSS 9.8No exploitEPSS 2%

    exponentcms · exponent cmsMay 24, 2019

  • In framework/modules/core/controllers/expCommentController.php of Exponent CMS 2.4.0, content_id input is passed into showComments.

    CriticalCVSS 9.8No exploitEPSS 2%

    exponentcms · exponent cmsNov 29, 2016

  • CVE-2016-7453
    39Monitor

    The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to perform an fid SQL Injection.

    CriticalCVSS 9.8No exploitEPSS 1%

    exponentcms · exponent cmsNov 3, 2016