CVE-2019-5956
https://notcve.org/view.php?id=CVE-2019-5956
Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors. Una vulnerabilidad de salto de directorio en WonderCMS versión 2.6.0 y anteriores, permite a atacantes remotos eliminar archivos arbitrarios por medio de vectores no especificados. • http://jvn.jp/en/vu/JVNVU93628467/index.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2018-14387
https://notcve.org/view.php?id=CVE-2018-14387
An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authenticate against the server using the same session identifier. The attacker can access the user's account through the active session. The Session Fixation attack fixes a session on the victim's browser, so the attack starts before the user logs in. • https://github.com/robiso/wondercms/issues/64 https://www.wondercms.com/whatsnew • CWE-384: Session Fixation •
CVE-2018-7172
https://notcve.org/view.php?id=CVE-2018-7172
In index.php in WonderCMS before 2.4.1, remote attackers can delete arbitrary files via directory traversal. En index.php en WonderCMS, en versiones anteriores a la 2.4.1, los atacantes remotos pueden eliminar archivos arbitrarios mediante salto de directorio. • http://foreversong.cn/archives/1070 https://github.com/robiso/wondercms/commit/64efdc4fd974c83cedd221b46e7c3854a81650ec https://www.wondercms.com/whatsnew • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2017-7951
https://notcve.org/view.php?id=CVE-2017-7951
WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context. WonderCMS en versiones anteriores a 2.0.3 tiene CSRF debido a la falta de un token en un contexto no especificado. • https://github.com/robiso/wondercms/releases/tag/2.0.3 https://www.wondercms.com/forum/viewtopic.php?f=8&p=1684 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2011-5317
https://notcve.org/view.php?id=CVE-2011-5317
Cross-site scripting (XSS) vulnerability in editText.php in WonderCMS before 0.4 allows remote attackers to inject arbitrary web script or HTML via the content parameter. Vulnerabilidad de XSS en editText.php en WonderCMS anterior a 0.4 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro content. • https://www.htbridge.com/advisory/HTB22759 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •