← Back

Onefilecms

onefilecms

6 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Onefilecms
onefilecms

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Onefilecms
1Onefilecms
Nov 21, 2024
Feb 17, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice.
1Onefilecms
1Onefilecms
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by ?i=etc/&f=passwd&p=raw_view for the /etc/passwd file.
1Onefilecms
1Onefilecms
Nov 21, 2024
Jul 3, 2018
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrated by a ?i=var/www/html/&f=123.php&p=edit&p=deletefile URI.
1Onefilecms
1Onefilecms
Nov 21, 2024
Jun 29, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen.
1Onefilecms
1Onefilecms
Nov 21, 2024
Jun 29, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screen.
1Onefilecms
1Onefilecms
Nov 21, 2024
Jun 29, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields.