Page 2 of 19 results (0.006 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

17 Jul 2018 — manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets the $errm value, and does not otherwise alter the flow of control. Consequently, one can upload and execute a .php file, a similar issue to CVE-2018-8766. manager/editor/upload.php en joyplus-cms 1.6.0 permite la subida de archivos arbitrarios debido a que una detección de una extensión de archivo prohibida simplemente establece el valor $errm y no altera el flujo de contr... • https://github.com/joyplus/joyplus-cms/issues/428 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

27 Jun 2018 — joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions. joyplus-cms 1.6.0 tiene Cross-Site Scripting (XSS) en admin_player.php, relacionado con las acciones "system manage" y "add" en manager/index.php. • https://github.com/joyplus/joyplus-cms/issues/427 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 8%CPEs: 1EXPL: 1

07 Jun 2018 — joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "/!select/" substring in place of a select substring. joyplus-cms 1.6.0 permite la ejecución remota de código debido a un problema de ejecución de comandos SQL arbitrarios en manager/index.php relacionados con el uso de una subcadena "/!select/" en lugar de una subcadena select. • https://github.com/joyplus/joyplus-cms/issues/425 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

13 Apr 2018 — joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request. joyplus-cms 1.6.0 tiene Cross-Site Scripting (XSS) mediante el parámetro device_name en una petición manager/admin_ajax.php?action=save flag=add. • https://github.com/joyplus/joyplus-cms/issues/424 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

12 Apr 2018 — joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter. joyplus-cms 1.6.0 tiene Cross-Site Scripting (XSS) en manager/admin_vod.php mediante el parámetro keyword. • https://github.com/joyplus/joyplus-cms/issues/423 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

11 Apr 2018 — joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI. joyplus-cms 1.6.0 permite que los atacantes remotos obtengan información sensible mediante una petición directa a los URI install/ o log/. • https://github.com/joyplus/joyplus-cms/issues/422 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 9.8EPSS: 2%CPEs: 1EXPL: 1

18 Mar 2018 — joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.php?action=add. joyplus-cms 1.6.0 permite la ejecución remota de código debido a un problema de subida de archivos arbitrarios en manager/editor/upload.php. Esto está relacionado con manager/admin_vod.php?action=add. • https://github.com/joyplus/joyplus-cms/issues/421 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

18 Mar 2018 — joyplus-cms 1.6.0 has XSS in manager/admin_ajax.php?action=save&tab={pre}vod_type via the t_name parameter. joyplus-cms 1.6.0 tiene Cross-Site Scripting (XSS) en manager/admin_ajax.php?action=savetab={pre}vod_type mediante el parámetro t_name. • https://github.com/joyplus/joyplus-cms/issues/420 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

14 Mar 2018 — joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request. joyplus-cms 1.6.0 tiene Cross-Site Request Forgery (CSRF), tal y como demuestra la adición de una cuenta de administrador mediante una petición manager/admin_ajax.php?action=savetab={pre}manager. • https://github.com/joyplus/joyplus-cms/issues/419 • CWE-352: Cross-Site Request Forgery (CSRF) •