pulsecms records
9 published records for vendor pulsecms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2010-4330Proof of concept | Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic before 1.2.9 allows remote attackers to include and execute pulsecms · pulse cms · CWE-22 | Medium6.8 | — | 2.6% | Dec 7, 2010 |
27Monitor | CVE-2010-0992No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in Pulse CMS Basic 1.2.2 and 1.2.3, and possibly Pulse Pro before 1.3.2, allow repulsecms · pulse cms · CWE-352 | Medium6.8 | — | 0.6% | Apr 9, 2010 |
24Monitor | CVE-2010-0993No exploit | Unrestricted file upload vulnerability in Pulse CMS Basic 1.2.2 and 1.2.3, and possibly Pulse Pro before 1.3.2, allows remote authenticated pulsecms · pulse cms | Medium6.0 | — | 1.6% | Apr 9, 2010 |
24Monitor | CVE-2010-1334No exploit | Unrestricted file upload vulnerability in Pulse CMS Basic 1.2.4 allows remote authenticated users to execute arbitrary code by uploading a fpulsecms · pulse cms | Medium6.0 | — | 1.3% | Apr 9, 2010 |
24Monitor | CVE-2010-0988No exploit | Multiple unspecified vulnerabilities in Pulse CMS before 1.2.3 allow (1) remote attackers to write to arbitrary files and execute arbitrary pulsecms · pulse cms · CWE-94 | Medium6.0 | — | 1.2% | Mar 26, 2010 |
22Monitor | CVE-2010-0989No exploit | Directory traversal vulnerability in delete.php in Pulse CMS before 1.2.3 allows remote authenticated users to delete arbitrary files via dipulsecms · pulse cms · CWE-22 | Medium5.5 | — | 1.3% | Mar 26, 2010 |
17Monitor | CVE-2011-5041Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary web script or HTML viapulsecms · pulse cms · CWE-79 | Medium4.3 | — | 1.5% | Dec 30, 2011 |
17Monitor | CVE-2010-1080No exploit | Cross-site scripting (XSS) vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via tpulsecms · pulse cms · CWE-79 | Medium4.3 | — | 1.1% | Mar 23, 2010 |
16Monitor | CVE-2010-1298No exploit | Directory traversal vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to read arbitrary files via directory traversal seqpulsecms · pulse cms · CWE-22 | Medium4.0 | — | 1.2% | Apr 6, 2010 |
- CVE-2010-433028Monitor
Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic before 1.2.9 allows remote attackers to include and execute
MediumCVSS 6.8Proof of conceptEPSS 3%pulsecms · pulse cmsDec 7, 2010
- CVE-2010-099227Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Pulse CMS Basic 1.2.2 and 1.2.3, and possibly Pulse Pro before 1.3.2, allow re
MediumCVSS 6.8No exploitEPSS 1%pulsecms · pulse cmsApr 9, 2010
- CVE-2010-099324Monitor
Unrestricted file upload vulnerability in Pulse CMS Basic 1.2.2 and 1.2.3, and possibly Pulse Pro before 1.3.2, allows remote authenticated
MediumCVSS 6.0No exploitEPSS 2%pulsecms · pulse cmsApr 9, 2010
- CVE-2010-133424Monitor
Unrestricted file upload vulnerability in Pulse CMS Basic 1.2.4 allows remote authenticated users to execute arbitrary code by uploading a f
MediumCVSS 6.0No exploitEPSS 1%pulsecms · pulse cmsApr 9, 2010
- CVE-2010-098824Monitor
Multiple unspecified vulnerabilities in Pulse CMS before 1.2.3 allow (1) remote attackers to write to arbitrary files and execute arbitrary
MediumCVSS 6.0No exploitEPSS 1%pulsecms · pulse cmsMar 26, 2010
- CVE-2010-098922Monitor
Directory traversal vulnerability in delete.php in Pulse CMS before 1.2.3 allows remote authenticated users to delete arbitrary files via di
MediumCVSS 5.5No exploitEPSS 1%pulsecms · pulse cmsMar 26, 2010
- CVE-2011-504117Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary web script or HTML via
MediumCVSS 4.3Proof of conceptEPSS 1%pulsecms · pulse cmsDec 30, 2011
- CVE-2010-108017Monitor
Cross-site scripting (XSS) vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via t
MediumCVSS 4.3No exploitEPSS 1%pulsecms · pulse cmsMar 23, 2010
- CVE-2010-129816Monitor
Directory traversal vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to read arbitrary files via directory traversal seq
MediumCVSS 4.0No exploitEPSS 1%pulsecms · pulse cmsApr 6, 2010