Skip to main content

Vendor/product archive

lucidcrew / pixie CVEs

Beta · best-effort

9 CVEs tagged to lucidcrew / pixie1 Critical, 1 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2017-7402

Published Apr 3, 2017

Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7363

Published Mar 31, 2017

Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7362

Published Mar 31, 2017

Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7361

Published Mar 31, 2017

Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3786

Published Jun 4, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitrary web script or HT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4710

Published Dec 8, 2011

Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTT…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3793

Published Sep 24, 2011

Pixie 1.04 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1