Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zikula Application Framework CRITICAL 9.8
CVE-2014-2293

Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or exec…

Fix: after 1.3.6
Fix from $2,300 2018-03-26
Zikula Application Framework CRITICAL 9.8
CVE-2016-9835

Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to laun…

Patch available
Fix from $2,300 2016-12-05
Zikula MEDIUM 5.0
CVE-2011-3826

Zikula 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an e…

Mitigation only
Fix from $1,600 2011-09-24
Zikula Application Framework MEDIUM 6.8
CVE-2011-0535

Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of ad…

Fix: after 1.2.4
Fix from $1,600 2011-02-08
Zikula Application Framework MEDIUM 6.8
CVE-2010-4729

Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier f…

Fix: after 1.2.2
Fix from $1,600 2011-02-08
Zikula Application Framework MEDIUM 5.0
CVE-2010-4728

Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protecti…

Fix: after 1.2.5
Fix from $1,600 2011-02-08
Zikula Application Framework MEDIUM 6.8
CVE-2010-1732

Cross-site request forgery (CSRF) vulnerability in the users module in Zikula Application Framework before 1.2.3 allows remote attackers to hijack th…

Fix: after 1.2.2
Fix from $1,600 2010-05-06