Skip to content
Noroxi

Zikula records

11 published records for vendor zikula.

All records

11 records
  • Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary file

    CriticalCVSS 9.8No exploitEPSS 5%

    zikula · zikula application frameworkMar 26, 2018

  • Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacke

    CriticalCVSS 9.8No exploitEPSS 4%

    zikula · zikula application frameworkDec 5, 2016

  • CVE-2011-0535
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authenticat

    MediumCVSS 6.8Proof of conceptEPSS 1%

    zikula · zikula application frameworkFeb 8, 2011

  • CVE-2010-4729
    27Monitor

    Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it

    MediumCVSS 6.8No exploitEPSS 1%

    zikula · zikula application frameworkFeb 8, 2011

  • CVE-2010-1732
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in the users module in Zikula Application Framework before 1.2.3 allows remote attackers to

    MediumCVSS 6.8No exploitEPSS 1%

    zikula · zikula application frameworkMay 6, 2010

  • CVE-2011-3826
    20Monitor

    Zikula 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pat

    MediumCVSS 5.0No exploitEPSS 1%

    zikula · zikulaSep 23, 2011

  • CVE-2010-4728
    20Monitor

    Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat

    MediumCVSS 5.0No exploitEPSS 1%

    zikula · zikula application frameworkFeb 8, 2011

  • CVE-2011-3979
    18Monitor

    Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Application

    MediumCVSS 4.3Proof of conceptEPSS 4%

    zikula · zikula application frameworkOct 4, 2011

  • CVE-2010-1724
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to i

    MediumCVSS 4.3Proof of conceptEPSS 4%

    zikula · zikula application frameworkMay 6, 2010

  • CVE-2013-6168
    17Monitor

    Cross-site scripting (XSS) vulnerability in Zikula Application Framework before 1.3.6 allows remote attackers to inject arbitrary web script

    MediumCVSS 4.3No exploitEPSS 1%

    zikula · zikula application frameworkNov 14, 2013

  • CVE-2011-0911
    17Monitor

    Cross-site scripting (XSS) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to inject arbitrary web script o

    MediumCVSS 4.3No exploitEPSS 1%

    zikula · zikula application frameworkFeb 8, 2011