Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Fiyo_cms
(Fiyo)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 26 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2017-07-26 | CVE-2017-11630 | dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter in a type=database request, a different vulnerability than CVE-2017-8853. | Fiyo_cms | 7.5 | ||
2017-07-18 | CVE-2017-11419 | Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title']. | Fiyo_cms | 9.8 | ||
2017-07-18 | CVE-2017-11418 | Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iSortCol_'.$i]. | Fiyo_cms | 9.8 | ||
2017-07-18 | CVE-2017-11417 | Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_status.php via $_GET['id']. | Fiyo_cms | 9.8 | ||
2017-07-18 | CVE-2017-11416 | Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter. | Fiyo_cms | 9.8 | ||
2017-07-18 | CVE-2017-11415 | Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/sys_article.php via $_POST['parent_id'], $_POST['desc'], $_POST['keys'], and $_POST['level']. | Fiyo_cms | 9.8 | ||
2017-07-18 | CVE-2017-11414 | Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/sys_comment.php via $_POST['comment'], $_POST['name'], $_POST['web'], $_POST['email'], $_POST['status'], $_POST['id'], and $_REQUEST['id']. | Fiyo_cms | 9.8 | ||
2017-07-18 | CVE-2017-11413 | Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/comment_status.php via $_GET['id']. | Fiyo_cms | 9.8 | ||
2017-07-18 | CVE-2017-11412 | Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/controller/comment_status.php via $_GET['id']. | Fiyo_cms | 9.8 | ||
2017-07-17 | CVE-2017-11354 | Fiyo CMS v2.0.7 has an SQL injection vulnerability in dapur/apps/app_article/sys_article.php via the name parameter in editing or adding a tag name. | Fiyo_cms | 9.8 |