Skip to main content

Vendor archive

pulsecms CVEs

Beta · best-effort

9 CVEs tagged to vendor pulsecms0 Critical, 0 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2011-5041

Published Dec 30, 2011

Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) d parameter in a blocks action…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4330

Published Dec 7, 2010

Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic before 1.2.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1334

Published Apr 9, 2010

Unrestricted file upload vulnerability in Pulse CMS Basic 1.2.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension follow…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0993

Published Apr 9, 2010

Unrestricted file upload vulnerability in Pulse CMS Basic 1.2.2 and 1.2.3, and possibly Pulse Pro before 1.3.2, allows remote authenticated users to execute arbitrary code by uplo…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0992

Published Apr 9, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in Pulse CMS Basic 1.2.2 and 1.2.3, and possibly Pulse Pro before 1.3.2, allow remote attackers to hijack the authentica…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1298

Published Apr 6, 2010

Directory traversal vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to read arbitrary files via directory traversal sequences in the f parameter. NOTE: the p…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0989

Published Mar 26, 2010

Directory traversal vulnerability in delete.php in Pulse CMS before 1.2.3 allows remote authenticated users to delete arbitrary files via directory traversal sequences in the f pa…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0988

Published Mar 26, 2010

Multiple unspecified vulnerabilities in Pulse CMS before 1.2.3 allow (1) remote attackers to write to arbitrary files and execute arbitrary PHP code via vectors related to imprope…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1080

Published Mar 23, 2010

Cross-site scripting (XSS) vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the f parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1