6 results (0.004 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors. Una vulnerabilidad de salto de directorio en WonderCMS versión 2.6.0 y anteriores, permite a atacantes remotos eliminar archivos arbitrarios por medio de vectores no especificados. • http://jvn.jp/en/vu/JVNVU93628467/index.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authenticate against the server using the same session identifier. The attacker can access the user's account through the active session. The Session Fixation attack fixes a session on the victim's browser, so the attack starts before the user logs in. • https://github.com/robiso/wondercms/issues/64 https://www.wondercms.com/whatsnew • CWE-384: Session Fixation •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

In index.php in WonderCMS before 2.4.1, remote attackers can delete arbitrary files via directory traversal. En index.php en WonderCMS, en versiones anteriores a la 2.4.1, los atacantes remotos pueden eliminar archivos arbitrarios mediante salto de directorio. • http://foreversong.cn/archives/1070 https://github.com/robiso/wondercms/commit/64efdc4fd974c83cedd221b46e7c3854a81650ec https://www.wondercms.com/whatsnew • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOTE: the vendor disputes this issue stating that this is a feature that enables only a logged in administrator to write execute JavaScript anywhere on their website ** EN DISPUTA ** En WonderCMS 2.3.1, los campos de entrada de la aplicación aceptan entradas arbitrarias de usuario, lo que resulta en la ejecución de JavaScript malicioso. NOTA: el fabricante discute este problema diciendo que esta es una característica que permite que solo un administrador que haya iniciado sesión escriba o ejecute JavaScript en cualquier sitio de su web. • https://securitywarrior9.blogspot.in/2018/01/stored-xss-in-wonder-cms.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 2

In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload. En WonderCMS 2.3.1, la funcionalidad de subida acepta extensiones de aplicación aleatorias y conduce a la subida de archivos maliciosa. Wonder CMS version 2.3.1 suffers from an unrestricted file upload vulnerability. • https://www.exploit-db.com/exploits/43963 https://securitywarrior9.blogspot.in/2018/01/vulnerability-in-wonder-cms-leading-to.html • CWE-434: Unrestricted Upload of File with Dangerous Type •