Products: 2
    Vulnerabilities: 8
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-6127

    An issue was discovered in XiaoCms 20141229. It allows admin/index.php?c=database table[] SQL injection. This can be used for PHP code execution via "INTO OUTFILE" with a .php filename.

    Last Modified: Nov 21, 2024
    Published: Jan 11, 2019

    CVE-2018-19192

    An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content] parameter.

    Last Modified: Nov 21, 2024
    Published: Nov 12, 2018

    CVE-2018-19195

    An issue was discovered in XiaoCms 20141229. There is XSS related to the template\default\show_product.html file.

    Last Modified: Nov 21, 2024
    Published: Nov 12, 2018

    CVE-2018-19197

    An issue was discovered in XiaoCms 20141229. admin\controller\database.php allows arbitrary directory deletion via admin/index.php?c=database&a=import&paths[]=../ directory traversal.

    Last Modified: Nov 21, 2024
    Published: Nov 12, 2018

    CVE-2018-19193

    An issue was discovered in XiaoCms 20141229. There is XSS via the largest input box on the "New news" screen.

    Last Modified: Nov 21, 2024
    Published: Nov 12, 2018
    Items Per Page