A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or …
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.
*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php…
Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.
Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().
A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.
emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafted Zip file.
emlog v6.0.0 contains a SQL injection via /admin/comment.php.
emlog v6.0.0 contains an arbitrary file deletion vulnerability in admin/plugin.php.
An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement and query server sensitive da…
Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script as a link to a new blog post.
emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
Cross Site Scripting (XSS) vulnerability in the article comments feature in emlog 6.0.
Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.
emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.
emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.