Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Auracms HIGH 8.8
CVE-2018-16338

An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subseq…

No fix yet
Fix from $1,950 2018-09-02
Auracms MEDIUM 5.4
CVE-2018-15199

AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.

No fix yet
Fix from $1,600 2018-08-08
Auracms MEDIUM 5.0
CVE-2014-3975EPSS 7%

Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in the viewdi…

No fix yet
Fix from $1,600 2014-06-05
Auracms MEDIUM 6.5
CVE-2014-1401

Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) sear…

Fix: after 2.3
Fix from $1,600 2014-02-11
Auracms HIGH 7.5
CVE-2010-4774

SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different ve…

No fix yet
Fix from $1,950 2011-03-23
Auracms HIGH 7.5
CVE-2008-3203

js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web cont…

No fix yet
Fix from $1,950 2008-07-17
Auracms MEDIUM 6.8
CVE-2008-1715

SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute a…

Fix: after 2.2.1
Fix from $1,600 2008-04-09
Auracms MEDIUM 6.8
CVE-2008-1398

SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-…

No fix yet
Fix from $1,600 2008-03-20
Auracms HIGH 7.5
CVE-2008-0811

Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1) the kid parameter to (a) mod/…

No fix yet
Fix from $1,950 2008-02-19
Auracms HIGH 10.0
CVE-2008-0735

SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the alb…

No fix yet
Fix from $1,950 2008-02-13
Auracms HIGH 7.5
CVE-2008-0390

stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via the X-Forw…

No fix yet
Fix from $1,950 2008-01-23
Auracms MEDIUM 6.0
CVE-2007-6552

Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a ..…

No fix yet
Fix from $1,600 2007-12-28
Auracms HIGH 7.5
CVE-2007-4905EPSS 7%

Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitrary PHP files via the ima…

No fix yet
Fix from $1,950 2007-09-17
Auracms HIGH 7.5
CVE-2007-4908

Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a …

No fix yet
Fix from $1,950 2007-09-17
Auracms MEDIUM 6.8
CVE-2007-4886

Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a (1) UNC s…

No fix yet
Fix from $1,600 2007-09-14
Auracms HIGH 7.5
CVE-2007-4804

Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php,…

No fix yet
Fix from $1,950 2007-09-11
Modul Forum Sederhana HIGH 7.5
CVE-2007-4171

SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers to execute arbitrary SQL …

No fix yet
Fix from $1,950 2007-08-07