CVE-2018-10096
https://notcve.org/view.php?id=CVE-2018-10096
joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request. joyplus-cms 1.6.0 tiene Cross-Site Scripting (XSS) mediante el parámetro device_name en una petición manager/admin_ajax.php?action=save flag=add. • https://github.com/joyplus/joyplus-cms/issues/424 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-10073
https://notcve.org/view.php?id=CVE-2018-10073
joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter. joyplus-cms 1.6.0 tiene Cross-Site Scripting (XSS) en manager/admin_vod.php mediante el parámetro keyword. • https://github.com/joyplus/joyplus-cms/issues/423 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-10028
https://notcve.org/view.php?id=CVE-2018-10028
joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI. joyplus-cms 1.6.0 permite que los atacantes remotos obtengan información sensible mediante una petición directa a los URI install/ o log/. • https://github.com/joyplus/joyplus-cms/issues/422 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-8766
https://notcve.org/view.php?id=CVE-2018-8766
joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.php?action=add. joyplus-cms 1.6.0 permite la ejecución remota de código debido a un problema de subida de archivos arbitrarios en manager/editor/upload.php. Esto está relacionado con manager/admin_vod.php?action=add. • https://github.com/joyplus/joyplus-cms/issues/421 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2018-8767
https://notcve.org/view.php?id=CVE-2018-8767
joyplus-cms 1.6.0 has XSS in manager/admin_ajax.php?action=save&tab={pre}vod_type via the t_name parameter. joyplus-cms 1.6.0 tiene Cross-Site Scripting (XSS) en manager/admin_ajax.php?action=savetab={pre}vod_type mediante el parámetro t_name. • https://github.com/joyplus/joyplus-cms/issues/420 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •