Cuppa CMS 漏洞列表
共找到 25 个与 Cuppa CMS 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2022-24264: Cuppa CMS v1.0 - SQL injection POC
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter. -
CVE-2022-24265: Cuppa CMS v1.0 - SQL injection POC
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter. -
CVE-2022-24266: Cuppa CMS v1.0 - SQL injection POC
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter. -
CVE-2022-25485: Cuppa CMS v1.0 - Local File Inclusion POC
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php. -
CVE-2022-25486: Cuppa CMS v1.0 - Local File Inclusion POC
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php. -
CVE-2022-25497: Cuppa CMS v1.0 - Local File Inclusion POC
CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function. -
CVE-2022-27984: Cuppa CMS v1.0 - SQL injection POC
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php. -
CVE-2022-27985: Cuppa CMS v1.0 - SQL injection POC
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php. -
CVE-2022-37190: Cuppa CMS v1.0 - Remote Code Execution POC
CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php. -
CVE-2022-37191: Cuppa CMS v1.0 - Authenticated Local File Inclusion POC
The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload. -
CVE-2022-38295: Cuppa CMS v1.0 - Cross Site Scripting POC
Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function. -
CVE-2022-38296: Cuppa CMS v1.0 - Arbitrary File Upload POC
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager. -
CVE-2022-24264: Cuppa CMS v1.0 - SQL injection POC
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter. -
CVE-2022-24265: Cuppa CMS v1.0 - SQL injection POC
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter. -
CVE-2022-24266: Cuppa CMS v1.0 - SQL injection POC
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter. -
CVE-2022-25485: Cuppa CMS v1.0 - Local File Inclusion POC
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php. -
CVE-2022-25486: Cuppa CMS v1.0 - Local File Inclusion POC
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php. -
CVE-2022-25497: Cuppa CMS v1.0 - Local File Inclusion POC
CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function. -
CVE-2022-27984: Cuppa CMS v1.0 - SQL injection POC
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php. -
CVE-2022-27985: Cuppa CMS v1.0 - SQL injection POC
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php. -
CVE-2022-37190: Cuppa CMS v1.0 - Remote Code Execution POC
CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php. -
CVE-2022-37191: Cuppa CMS v1.0 - Authenticated Local File Inclusion POC
The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload. -
CVE-2022-38295: Cuppa CMS v1.0 - Cross Site Scripting POC
Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function. -
CVE-2022-38296: Cuppa CMS v1.0 - Arbitrary File Upload POC
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager. -
Cuppa CMS CVE-2022-34121 目录遍历漏洞 无POC
Cuppa CMS存在目录遍历漏洞,此漏洞是由于缺乏验证导致的。