Page 2 of 10 results (0.009 seconds)

CVSS: 9.8EPSS: 16%CPEs: 1EXPL: 3

ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==). ImpressCMS versiones anteriores a 1.4.3, presenta una confusión de tipo en el archivo plugins/preloads/autologin.php con la consiguiente Omisión de Autenticación (!= en lugar de ! • http://karmainsecurity.com/KIS-2022-01 http://packetstormsecurity.com/files/166393/ImpressCMS-1.4.2-Authentication-Bypass.html http://seclists.org/fulldisclosure/2022/Mar/43 https://hackerone.com/reports/1081986 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVSS: 9.8EPSS: 3%CPEs: 1EXPL: 1

ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP installation supports upload_progress. ImpressCMS versiones anteriores a 1.4.2, permite una ejecución de código remota no autenticado por medio de .....// salto de directorio en origName or imageName, conllevando a una interacción no segura con el script CKEditor processImage.php. La carga útil puede ser colocada en PHP_SESSION_UPLOAD_PROGRESS cuando la instalación de PHP soporta upload_progress • https://github.com/ImpressCMS/impresscms/commit/a66d7bb499faafab803e24833606028fa0ba4261 https://github.com/ImpressCMS/impresscms/compare/1.4.1...v1.4.2 https://r0.haxors.org/posts?id=8 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 6.4EPSS: 23%CPEs: 1EXPL: 2

Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_path parameter in a cancel action. Vulnerabilidad de salto de ruta absoluta en htdocs/libraries/image-editor/image-edit.php en ImpressCMS anterior a 1.3.6 permite a atacantes remotos eliminar ficheros arbitrarios a través de un nombre de ruta completo en el parámetro image_path en una acción de cancelar. ImpressCMS version 1.3.5 suffers from arbitrary file deletion and cross site scripting vulnerabilities. • https://www.exploit-db.com/exploits/31431 http://community.impresscms.org/modules/smartsection/item.php?itemid=675 http://osvdb.org/show/osvdb/102770 http://seclists.org/fulldisclosure/2014/Feb/14 http://www.securityfocus.com/bid/65279 https://github.com/pedrib/PoC/blob/master/generic/impresscms-1.3.5.txt • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 6.0EPSS: 1%CPEs: 17EXPL: 2

Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the icmsConfigPlugins[sanitizer_plugins][] parameter. Vulnerabilidad de salto de directorio en edituser.php en ImpressCMS v1.2.x anterior a v1.2.7 Final y v1.3.x anterior a v1.3.1 Final permite a usuarios remotos autenticados incluir y ejecutar ficheros locales arbitrarios mediante un .. (punto punto) en el parámetro icmsConfigPlugins[sanitizer_plugins][] • http://archives.neohapsis.com/archives/bugtraq/2012-01/0022.html http://community.impresscms.org/modules/smartsection/item.php?itemid=579 http://secunia.com/advisories/47448 http://www.osvdb.org/78143 http://www.securityfocus.com/bid/51268 https://exchange.xforce.ibmcloud.com/vulnerabilities/72146 https://www.htbridge.com/advisory/HTB23064 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 4.3EPSS: 0%CPEs: 17EXPL: 4

Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) notifications.php, (2) modules/system/admin/images/browser.php, and (3) modules/content/admin/content.php. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en ImpressCMS v1.2.x anterior a v1.2.7 Final y v1.3.x anterior a v1.3.1 Final permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de PATH_INFO para (1) notifications.php, (2) modules/system/admin/images/browser.php, y (3) modules/content/admin/content.php. • http://archives.neohapsis.com/archives/bugtraq/2012-01/0022.html http://community.impresscms.org/modules/smartsection/item.php?itemid=579 http://secunia.com/advisories/47448 http://www.osvdb.org/78140 http://www.osvdb.org/78141 http://www.osvdb.org/78142 http://www.securityfocus.com/bid/51268 https://exchange.xforce.ibmcloud.com/vulnerabilities/72145 https://www.htbridge.com/advisory/HTB23064 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •