Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Minicms
(1234n)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 28 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-07-05 | CVE-2019-13341 | In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie. | Minicms | 4.8 | ||
2019-07-05 | CVE-2019-13340 | In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186. | Minicms | 4.8 | ||
2019-07-05 | CVE-2019-13339 | In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie. | Minicms | 4.8 | ||
2019-03-06 | CVE-2019-9603 | MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891. | Minicms | 6.5 | ||
2018-03-27 | CVE-2018-9092 | There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password. | Minicms | 8.8 | ||
2018-12-27 | CVE-2018-20520 | MiniCMS V1.10 has XSS via the mc-admin/post-edit.php query string, a related issue to CVE-2018-10296 and CVE-2018-16233. | Minicms | 6.1 | ||
2018-11-01 | CVE-2018-18892 | MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php. | Minicms | 9.8 | ||
2018-11-01 | CVE-2018-18891 | MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late. | Minicms | 7.5 | ||
2018-11-01 | CVE-2018-18890 | MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename. | Minicms | 5.3 | ||
2018-09-14 | CVE-2018-17039 | MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled. | Minicms | 6.1 |