Vulnerabilities
Vulnerable Software
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit/1 Body field.
CVSS Score
5.4
EPSS Score
0.002
Published
2019-02-11
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI.
CVSS Score
7.2
EPSS Score
0.011
Published
2019-02-11
Frog CMS 0.9.5 provides a directory listing for a /public request.
CVSS Score
7.5
EPSS Score
0.003
Published
2019-02-11
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit/1 Body field.
CVSS Score
5.4
EPSS Score
0.002
Published
2019-02-11
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows XSS by creating a new file containing a crafted attribute of an IMG element.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-02-11
Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI.
CVSS Score
7.2
EPSS Score
0.011
Published
2019-02-11
Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.
CVSS Score
7.2
EPSS Score
0.011
Published
2019-02-11
Frog CMS 0.9.5 allows XSS via the forgot password page (aka the /admin/?/login/forgot URI).
CVSS Score
6.1
EPSS Score
0.002
Published
2019-01-12
Frog CMS 0.9.5 has XSS in the admin/?/page/edit/1 body field.
CVSS Score
4.8
EPSS Score
0.002
Published
2019-01-09
Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-12-25


Contact Us

Shodan ® - All rights reserved