onefilecms records
6 published records for vendor onefilecms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2018-13123No exploit | onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated byonefilecms · onefilecms · CWE-200 | Critical9.8 | — | 1.4% | Jul 3, 2018 |
39Monitor | CVE-2018-12993No exploit | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefileonefilecms · onefilecms · CWE-307 | Critical9.8 | — | 1.2% | Jun 29, 2018 |
35Monitor | CVE-2018-12994No exploit | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screonefilecms · onefilecms · CWE-94 | High8.8 | — | 1.2% | Jun 29, 2018 |
35Monitor | CVE-2018-12995No exploit | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screenonefilecms · onefilecms · CWE-94 | High8.8 | — | 1.2% | Jun 29, 2018 |
26Monitor | CVE-2018-13122No exploit | onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstratonefilecms · onefilecms · CWE-732 | Medium6.5 | — | 0.8% | Jul 3, 2018 |
19Monitor | CVE-2019-8408No exploit | OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice.onefilecms · onefilecms | Medium4.9 | — | 1.2% | Feb 17, 2019 |
- CVE-2018-1312339Monitor
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by
CriticalCVSS 9.8No exploitEPSS 1%onefilecms · onefilecmsJul 3, 2018
- CVE-2018-1299339Monitor
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefile
CriticalCVSS 9.8No exploitEPSS 1%onefilecms · onefilecmsJun 29, 2018
- CVE-2018-1299435Monitor
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File scre
HighCVSS 8.8No exploitEPSS 1%onefilecms · onefilecmsJun 29, 2018
- CVE-2018-1299535Monitor
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen
HighCVSS 8.8No exploitEPSS 1%onefilecms · onefilecmsJun 29, 2018
- CVE-2018-1312226Monitor
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrat
MediumCVSS 6.5No exploitEPSS 1%onefilecms · onefilecmsJul 3, 2018
- CVE-2019-840819Monitor
OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice.
MediumCVSS 4.9No exploitEPSS 1%onefilecms · onefilecmsFeb 17, 2019