
CVE-2024-35527
https://notcve.org/view.php?id=CVE-2024-35527
25 Jun 2024 — An arbitrary file upload vulnerability in /fileupload/upload.cfm in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to execute arbitrary code via uploading a crafted .cfm file. Una vulnerabilidad de carga de archivos arbitrarios en /fileupload/upload.cfm en Daemon PTY Limited FarCry Core framework anterior a 7.2.14 permite a los atacantes ejecutar código arbitrario cargando un archivo .cfm manipulado. • https://bastionsecurity.co.nz/advisories/farcry-core-multiple.html • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2018-25055 – FarCry Solr Pro Plugin Search solrProSearch.cfc cross site scripting
https://notcve.org/view.php?id=CVE-2018-25055
28 Dec 2022 — A vulnerability was found in FarCry Solr Pro Plugin up to 1.5.x. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file packages/forms/solrProSearch.cfc of the component Search Handler. The manipulation of the argument suggestion leads to cross site scripting. The attack can be launched remotely. • https://github.com/jeffcoughlin/farcrysolrpro/commit/b8f3d61511c9b02b781ec442bfb803cbff8e08d5 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2005-4395
https://notcve.org/view.php?id=CVE-2005-4395
20 Dec 2005 — Cross-site scripting (XSS) vulnerability in FarCry 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the criteria parameter. • http://pridels0.blogspot.com/2005/12/farcry-xss-vuln.html •