Jflyfox
jflyfox
51 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (51)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list. |
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list. |
JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user. |
Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list. |
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module. |
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request. |
Jfinal cms 5.1.0 is vulnerable to SQL Injection. |
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor. |
Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java. |