Page 2 of 18 results (0.002 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

Frog CMS 0.9.5 provides a directory listing for a /public request. Frog CMS 0.9.5 proporciona una lista de directorios para una petición /public. • https://github.com/philippe/FrogCMS/issues/21 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI. admin/?/plugin/file_manager en Frog CMS 0.9.5 permite la ejecución de código PHP creando un nuevo archivo .php que contiene código PHP y visitando dicho archivo bajo el URI public/. • https://github.com/philippe/FrogCMS/issues/27 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI. Frog CMS 0.9.5 permite la ejecución de código PHP mediante un URI • https://github.com/philippe/FrogCMS/issues/24 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

Frog CMS 0.9.5 allows XSS via the forgot password page (aka the /admin/?/login/forgot URI). Frog CMS 0.9.5 permite Cross-Site Scripting (XSS) mediante la página de contraseña olvidada (URI /admin/?/login/forgot). • https://somerandomshitwbu.blogspot.com/2019/01/another-xss-on-frog-cms-open-source.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

Frog CMS 0.9.5 has XSS in the admin/?/page/edit/1 body field. Frog CMS 0.9.5 tiene Cross-Site Scripting (XSS) en el campo del cuerpo en admin/?/page/edit/1. • https://github.com/philippe/FrogCMS/issues/22 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •