Skip to content
Noroxi

onefilecms records

6 published records for vendor onefilecms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

6 records
  • onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by

    CriticalCVSS 9.8No exploitEPSS 1%

    onefilecms · onefilecmsJul 3, 2018

  • onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefile

    CriticalCVSS 9.8No exploitEPSS 1%

    onefilecms · onefilecmsJun 29, 2018

  • onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File scre

    HighCVSS 8.8No exploitEPSS 1%

    onefilecms · onefilecmsJun 29, 2018

  • onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen

    HighCVSS 8.8No exploitEPSS 1%

    onefilecms · onefilecmsJun 29, 2018

  • onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrat

    MediumCVSS 6.5No exploitEPSS 1%

    onefilecms · onefilecmsJul 3, 2018

  • CVE-2019-8408
    19Monitor

    OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice.

    MediumCVSS 4.9No exploitEPSS 1%

    onefilecms · onefilecmsFeb 17, 2019