Перейти к содержимому
Noroxi

Записи bigtreecms

45 опубликованных записей вендора bigtreecms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

45 записей
  • CVE-2018-10574
    40В плане

    site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the B

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    bigtreecms · bigtree cms30 апр. 2018 г.

  • CVE-2017-7695
    40В плане

    Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety ch

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    bigtreecms · bigtree cms11 апр. 2017 г.

  • CVE-2017-9364
    39Наблюдать

    Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    bigtreecms · bigtree cms2 июн. 2017 г.

  • CVE-2017-9442
    36Наблюдать

    BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web s

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    bigtreecms · bigtree cms5 июн. 2017 г.

  • CVE-2020-26670
    36Наблюдать

    A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands t

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    bigtreecms · bigtree cms1 июн. 2021 г.

  • CVE-2017-9427
    35Наблюдать

    SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    bigtreecms · bigtree cms4 июн. 2017 г.

  • CVE-2020-26668
    35Наблюдать

    A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attac

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bigtreecms · bigtree cms1 июн. 2021 г.

  • CVE-2017-9443
    35Наблюдать

    BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json i

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bigtreecms · bigtree cms5 июн. 2017 г.

  • CVE-2017-9449
    35Наблюдать

    SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bigtreecms · bigtree cms6 июн. 2017 г.

  • CVE-2017-11736
    35Наблюдать

    SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbi

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bigtreecms · bigtree cms29 июл. 2017 г.

  • CVE-2017-7881
    35Наблюдать

    BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing th

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bigtreecms · bigtree cms15 апр. 2017 г.

  • CVE-2017-9365
    35Наблюдать

    CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?fo

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    bigtreecms · bigtree cms2 июн. 2017 г.

  • CVE-2017-9379
    35Наблюдать

    Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.p

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    bigtreecms · bigtree cms2 июн. 2017 г.

  • CVE-2017-9444
    35Наблюдать

    BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.p

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    bigtreecms · bigtree cms5 июн. 2017 г.

  • CVE-2018-17341
    33Наблюдать

    BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ su

    ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %

    bigtreecms · bigtree cms23 сент. 2018 г.

  • CVE-2013-4879
    31Наблюдать

    SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    bigtreecms · bigtree cms14 авг. 2013 г.

  • CVE-2018-17030
    31Наблюдать

    BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    bigtreecms · bigtree cms13 сент. 2018 г.

  • CVE-2017-9428
    31Наблюдать

    A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    bigtreecms · bigtree cms4 июн. 2017 г.

  • CVE-2013-4881
    28Наблюдать

    Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote atta

    СредняяCVSS 6,8Proof of conceptEPSS 2 %

    bigtreecms · bigtree cms19 авг. 2013 г.

  • CVE-2017-6914
    28Наблюдать

    CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page.

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    bigtreecms · bigtree cms15 мар. 2017 г.

  • CVE-2013-5313
    27Наблюдать

    Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote atta

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    bigtreecms · bigtree cms19 авг. 2013 г.

  • CVE-2017-16961
    26Наблюдать

    A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain inf

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    bigtreecms · bigtree cms27 нояб. 2017 г.

  • CVE-2017-9378
    26Наблюдать

    BigTree CMS through 4.2.18 does not prevent a user from deleting their own account.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    bigtreecms · bigtree cms2 июн. 2017 г.

  • CVE-2018-18308
    25Наблюдать

    In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload a

    СредняяCVSS 6,1Proof of conceptEPSS 4 %

    bigtreecms · bigtree cms16 окт. 2018 г.

  • CVE-2018-1000521
    24Наблюдать

    BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vu

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    bigtreecms · bigtree cms26 июн. 2018 г.