1234n MiniCMS 1.10

CPE Details

1234n MiniCMS 1.10
1.10
2018-10-23
13h18 +00:00
2018-10-23
13h18 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:1234n:minicms:1.10:*:*:*:*:*:*:*

Informations

Vendor

1234n

Product

minicms

Version

1.10

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-33387 2023-02-24 00h00 +00:00 Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.
9.6
Critical
CVE-2020-17999 2021-04-28 13h23 +00:00 Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php".
6.1
Medium
CVE-2020-36051 2021-01-05 20h12 +00:00 Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter.
7.5
High
CVE-2020-36052 2021-01-05 20h12 +00:00 Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.
9.8
Critical
CVE-2019-13341 2019-07-05 12h05 +00:00 In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie.
4.8
Medium
CVE-2019-13340 2019-07-05 12h05 +00:00 In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186.
4.8
Medium
CVE-2019-13339 2019-07-05 12h05 +00:00 In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie.
4.8
Medium
CVE-2019-13186 2019-07-03 14h07 +00:00 In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the tags box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, and CVE-2018-20520.
6.1
Medium
CVE-2019-9603 2019-03-06 19h00 +00:00 MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891.
6.5
Medium
CVE-2018-20520 2018-12-27 14h00 +00:00 MiniCMS V1.10 has XSS via the mc-admin/post-edit.php query string, a related issue to CVE-2018-10296 and CVE-2018-16233.
6.1
Medium
CVE-2018-18890 2018-11-01 01h00 +00:00 MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename.
5.3
Medium
CVE-2018-18891 2018-11-01 01h00 +00:00 MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late.
7.5
High
CVE-2018-18892 2018-11-01 01h00 +00:00 MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.
9.8
Critical
CVE-2018-17039 2018-09-14 05h00 +00:00 MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled.
6.1
Medium
CVE-2018-16298 2018-08-31 23h00 +00:00 An issue was discovered in MiniCMS 1.10. There is an mc-admin/post.php?tag= XSS vulnerability for a state=delete, state=draft, or state=publish request.
6.1
Medium
CVE-2018-16233 2018-08-30 20h00 +00:00 MiniCMS V1.10 has XSS via the mc-admin/post-edit.php tags parameter.
6.1
Medium
CVE-2018-15899 2018-08-27 02h00 +00:00 An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.
6.1
Medium
CVE-2018-10423 2018-04-26 05h00 +00:00 mc-admin/post.php in MiniCMS 1.10 allows remote attackers to obtain a directory listing of the top-level directory of the web root via a link that becomes available after posting an article.
2.7
Low
CVE-2018-10424 2018-04-26 05h00 +00:00 mc-admin/post-edit.php in MiniCMS 1.10 allows full path disclosure via a modified id field.
2.7
Low
CVE-2018-10296 2018-04-22 12h00 +00:00 MiniCMS V1.10 has XSS via the mc-admin/post-edit.php title parameter.
6.1
Medium
CVE-2018-10227 2018-04-19 08h00 +00:00 MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter.
5.4
Medium
CVE-2018-9092 2018-03-27 20h00 +00:00 There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.
8.8
High