İçeriğe atla
Noroxi

bigtreecms kayıtları

bigtreecms üreticisine ait 45 yayımlanmış kayıt.

Tüm kayıtlar

45 kayıt
  • CVE-2018-10574
    40Planlayın

    site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the B

    KritikCVSS 9,8İstismar yokEPSS %2

    bigtreecms · bigtree cms30 Nis 2018

  • CVE-2017-7695
    40Planlayın

    Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety ch

    KritikCVSS 9,8İstismar yokEPSS %2

    bigtreecms · bigtree cms11 Nis 2017

  • CVE-2017-9364
    39İzleyin

    Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a

    KritikCVSS 9,8İstismar yokEPSS %1

    bigtreecms · bigtree cms2 Haz 2017

  • CVE-2017-9442
    36İzleyin

    BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web s

    YüksekCVSS 8,8İstismar yokEPSS %2

    bigtreecms · bigtree cms5 Haz 2017

  • CVE-2020-26670
    36İzleyin

    A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands t

    YüksekCVSS 8,8İstismar yokEPSS %2

    bigtreecms · bigtree cms1 Haz 2021

  • CVE-2017-9427
    35İzleyin

    SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin

    YüksekCVSS 8,8İstismar yokEPSS %2

    bigtreecms · bigtree cms4 Haz 2017

  • CVE-2020-26668
    35İzleyin

    A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attac

    YüksekCVSS 8,8İstismar yokEPSS %1

    bigtreecms · bigtree cms1 Haz 2021

  • CVE-2017-9443
    35İzleyin

    BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json i

    YüksekCVSS 8,8İstismar yokEPSS %1

    bigtreecms · bigtree cms5 Haz 2017

  • CVE-2017-9449
    35İzleyin

    SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin

    YüksekCVSS 8,8İstismar yokEPSS %1

    bigtreecms · bigtree cms6 Haz 2017

  • CVE-2017-11736
    35İzleyin

    SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbi

    YüksekCVSS 8,8İstismar yokEPSS %1

    bigtreecms · bigtree cms29 Tem 2017

  • CVE-2017-7881
    35İzleyin

    BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing th

    YüksekCVSS 8,8İstismar yokEPSS %1

    bigtreecms · bigtree cms15 Nis 2017

  • CVE-2017-9365
    35İzleyin

    CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?fo

    YüksekCVSS 8,8İstismar yokEPSS %0

    bigtreecms · bigtree cms2 Haz 2017

  • CVE-2017-9379
    35İzleyin

    Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.p

    YüksekCVSS 8,8İstismar yokEPSS %0

    bigtreecms · bigtree cms2 Haz 2017

  • CVE-2017-9444
    35İzleyin

    BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.p

    YüksekCVSS 8,8İstismar yokEPSS %0

    bigtreecms · bigtree cms5 Haz 2017

  • CVE-2018-17341
    33İzleyin

    BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ su

    YüksekCVSS 8,1İstismar yokEPSS %2

    bigtreecms · bigtree cms23 Eyl 2018

  • CVE-2013-4879
    31İzleyin

    SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    bigtreecms · bigtree cms14 Ağu 2013

  • CVE-2018-17030
    31İzleyin

    BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-

    YüksekCVSS 7,5İstismar yokEPSS %2

    bigtreecms · bigtree cms13 Eyl 2018

  • CVE-2017-9428
    31İzleyin

    A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows

    YüksekCVSS 7,5İstismar yokEPSS %2

    bigtreecms · bigtree cms4 Haz 2017

  • CVE-2013-4881
    28İzleyin

    Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote atta

    OrtaCVSS 6,8Kavram kanıtıEPSS %2

    bigtreecms · bigtree cms19 Ağu 2013

  • CVE-2017-6914
    28İzleyin

    CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page.

    YüksekCVSS 7,1İstismar yokEPSS %0

    bigtreecms · bigtree cms15 Mar 2017

  • CVE-2013-5313
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote atta

    OrtaCVSS 6,8İstismar yokEPSS %1

    bigtreecms · bigtree cms19 Ağu 2013

  • CVE-2017-16961
    26İzleyin

    A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain inf

    OrtaCVSS 6,5İstismar yokEPSS %1

    bigtreecms · bigtree cms27 Kas 2017

  • CVE-2017-9378
    26İzleyin

    BigTree CMS through 4.2.18 does not prevent a user from deleting their own account.

    OrtaCVSS 6,5İstismar yokEPSS %1

    bigtreecms · bigtree cms2 Haz 2017

  • CVE-2018-18308
    25İzleyin

    In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload a

    OrtaCVSS 6,1Kavram kanıtıEPSS %4

    bigtreecms · bigtree cms16 Eki 2018

  • BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vu

    OrtaCVSS 6,1İstismar yokEPSS %1

    bigtreecms · bigtree cms26 Haz 2018