Skip to main content

Vendor/product archive

bloofox / bloofoxcms CVEs

Beta · best-effort

26 CVEs tagged to bloofox / bloofoxcms11 Critical, 5 High, 9 Medium, 1 Low, 0 Unrated.

CVE-2020-36082

Published Aug 11, 2023

File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34756

Published Jun 14, 2023

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34755

Published Jun 14, 2023

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34754

Published Jun 14, 2023

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34753

Published Jun 14, 2023

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34752

Published Jun 14, 2023

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34751

Published Jun 14, 2023

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34750

Published Jun 14, 2023

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-29597

Published Apr 13, 2023

bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27812

Published Apr 13, 2023

bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23151

Published Jan 26, 2023

bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28528

Published Apr 26, 2022

bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44610

Published Feb 24, 2022

Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) defau…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-44608

Published Feb 24, 2022

Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35762

Published Jun 16, 2021

bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-35761

Published Jun 16, 2021

bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35760

Published Jun 16, 2021

bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35759

Published Jun 16, 2021

bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36142

Published Jun 4, 2021

BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36141

Published Jun 4, 2021

BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36140

Published Jun 4, 2021

BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Loca…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36139

Published Jun 4, 2021

BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35709

Published Dec 25, 2020

bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4870

Published Oct 7, 2011

SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4522

Published Dec 31, 2009

Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter to index.php.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2