finecms_project CVE 脆弱性と CVE 一覧(21)

製品(CPE): — CVE 件数: 21

finecms_project 脆弱性概要

finecms_project 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

一般的な弱点パターンには vendor risk cross-site scripting、vendor risk sql injection, and vendor risk ssrf があり、vendor surface software deployment and vendor surface production workloads の利用場面で vendor impact session compromise and vendor impact data exposure などのリスクが生じる可能性があります。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 120 / 21 CVE 件数
«« 先頭 « 前へ 1 / 2 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2017-1000429 rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php. [email protected] 6.1 0.24% 2018-01-09 2024-11-21
CVE-2017-14195 The call_msg function in controllers/Form.php in dayrui FineCms 5.0.11 might have XSS related to the Referer HTTP header with Internet Explorer. [email protected] 6.1 0.24% 2017-09-07 2026-05-13
CVE-2017-14194 The out function in controllers/member/Login.php in dayrui FineCms 5.0.11 has XSS related to the Referer HTTP header with Internet Explorer. [email protected] 6.1 0.24% 2017-09-07 2026-05-13
CVE-2017-14193 The oauth function in controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the Referer HTTP header with Internet Explorer. [email protected] 6.1 0.24% 2017-09-07 2026-05-13
CVE-2017-14192 The checktitle function in controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the module field. [email protected] 6.1 0.24% 2017-09-07 2026-05-13
CVE-2017-13697 controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable. [email protected] 6.1 0.24% 2017-08-25 2026-05-13
CVE-2017-12774 finecms in 1.9.5\controllers\member\ContentController.php allows remote attackers to operate website database [email protected] 9.8 0.90% 2017-08-09 2026-05-13
CVE-2017-11202 FineCMS through 2017-07-12 allows XSS in visitors.php because JavaScript in visited URLs is not restricted either during logging or during the reading of logs, a different vulnerability than CVE-2017-11180. [email protected] 6.1 0.24% 2017-07-13 2026-05-13
CVE-2017-11201 application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS attacks by uploading an image via a route=images action. [email protected] 5.4 0.16% 2017-07-13 2026-05-13
CVE-2017-11200 SQL Injection exists in FineCMS through 2017-07-12 via the application/core/controller/excludes.php visitor_ip parameter. [email protected] 8.8 0.23% 2017-07-13 2026-05-13
CVE-2017-11198 Cross-site scripting (XSS) vulnerability in /application/lib/ajax/get_image.php in FineCMS through 2017-07-12 allows remote attackers to inject arbitrary web script or HTML via the folder, id, or name parameter. [email protected] 6.1 0.19% 2017-07-13 2026-05-13
CVE-2017-11167 FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add Site" action to enter this code after a ', sequence in a domain name, as demonstrated by the ',phpinfo() input value. [email protected] 9.8 0.80% 2017-07-12 2026-05-13
CVE-2017-11180 FineCMS through 2017-07-11 has stored XSS in the logging functionality, as demonstrated by an XSS payload in (1) the User-Agent header of an HTTP request or (2) the username entered on the login screen. [email protected] 6.1 0.24% 2017-07-12 2026-05-13
CVE-2017-11179 FineCMS through 2017-07-11 has stored XSS in route=admin when modifying user information, and in route=register when registering a user account. [email protected] 6.1 0.24% 2017-07-12 2026-05-13
CVE-2017-11178 In FineCMS through 2017-07-11, application/core/controller/style.php allows remote attackers to write to arbitrary files via the contents and filename parameters in a route=style action. For example, this can be used to overwrite a .php file because the file extension is not checked. [email protected] 7.5 0.12% 2017-07-12 2026-05-13
CVE-2017-10968 In FineCMS through 2017-07-07, application\core\controller\template.php allows remote PHP code execution by placing the code after "<?php" in a route=template request. [email protected] 9.8 1.12% 2017-07-07 2026-05-13
CVE-2017-10973 In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with a modified HTTP Host header. [email protected] 6.5 0.21% 2017-07-06 2026-05-13
CVE-2017-10967 In FineCMS before 2017-07-06, application\core\controller\config.php allows XSS in the (1) key_name, (2) key_value, and (3) meaning parameters. [email protected] 6.1 0.33% 2017-07-06 2026-05-13
CVE-2017-9252 andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the search page via the text-search parameter to index.php in a route=search action. [email protected] 6.1 0.24% 2017-05-28 2026-05-13
CVE-2017-9251 andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the sitename parameter to admin.php. [email protected] 6.1 0.24% 2017-05-28 2026-05-13
«« 先頭 « 前へ 1 / 2 次へ »
cvelogic Threat Intelligence