Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mozilocms HIGH 7.2
CVE-2024-44871EPSS 16%

An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a…

No fix yet
Fix from $1,950 2024-09-10
Mozilocms MEDIUM 6.1
CVE-2024-44872

A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user's browser …

No fix yet
Fix from $1,600 2024-09-10
Mozilocms MEDIUM 6.5
CVE-2024-29368

An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renam…

No fix yet
Fix from $1,600 2024-04-22
Mozilocms MEDIUM 6.1
CVE-2024-2245

Cross-Site Scripting vulnerability in moziloCMS version 2.0. By sending a POST request to the '/install.php' endpoint, a JavaScript payload could be …

Mitigation only
Fix from $1,600 2024-03-07
Mozilocms CRITICAL 9.1
CVE-2022-23357EPSS 20%

mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.

No fix yet
Fix from $2,300 2022-02-03
Mozilocms MEDIUM 5.4
CVE-2020-25394

A stored cross site scripting (XSS) vulnerability in moziloCMS 2.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a craf…

No fix yet
Fix from $1,600 2021-07-09
Mozilocms HIGH 7.5
CVE-2009-1368EPSS 6%

Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in the page param…

Patch available
Fix from $1,950 2009-04-22
Mozilocms MEDIUM 5.0
CVE-2009-1369

moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter…

No fix yet
Fix from $1,600 2009-04-22
Mozilocms MEDIUM 6.8
CVE-2008-6128

Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

Fix: after 1.10.2
Fix from $1,600 2009-02-13
Mozilowiki MEDIUM 6.0
CVE-2008-6131

Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

Fix: after 1.0.1
Fix from $1,600 2009-02-13
Mozilocms MEDIUM 5.0
CVE-2008-6126

Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the…

Fix: after 1.10.2
Fix from $1,600 2009-02-13