Neocrome Seditio vulnerabilities
8 known vulnerabilities affecting neocrome/seditio.
Total CVEs
8
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2009-1411P3HIGHCVSS 7.5PoCv1.02009-04-24
CVE-2009-1411 [HIGH] CWE-89 CVE-2009-1411: SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 al
SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the c parameter to plug.php.
nvd
CVE-2007-4057P3MEDIUMCVSS 6.5PoC≤ 1212007-07-30
CVE-2007-4057 [MEDIUM] CVE-2007-4057: Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and earlier allows remote
Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and earlier allows remote authenticated users to upload arbitrary PHP code via a filename ending with (1) .php.gif, (2) .php.jpg, or (3) .php.png.
nvd
CVE-2007-6202P3MEDIUMCVSS 6.8PoC≤ 1212007-12-01
CVE-2007-6202 [MEDIUM] CWE-89 CVE-2007-6202: SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier all
SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] parameter to plug.php.
nvd
CVE-2006-6177P4HIGHCVSS 7.5PoC≤ 1.102006-11-30
CVE-2006-6177 [HIGH] CVE-2006-6177: SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and
SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via a double-url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by an encoded NULL and ' (apostrophe) (%2500%2527).
nvd
CVE-2006-6343P4MEDIUMCVSS 6.8PoC≤ 1.102006-12-07
CVE-2006-6343 [MEDIUM] CVE-2006-6343: SQL injection vulnerability in polls.php in Neocrome Seditio 1.10 and earlier allows remote attacker
SQL injection vulnerability in polls.php in Neocrome Seditio 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
nvd
CVE-2006-6577P4MEDIUMCVSS 6.8PoCv1.102006-12-15
CVE-2006-6577 [MEDIUM] CVE-2006-6577: SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows re
SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
nvd
CVE-2006-6344P4HIGHCVSS 7.5≤ 1.102006-12-07
CVE-2006-6344 [HIGH] CVE-2006-6344: Multiple unspecified vulnerabilities in Neocrome Seditio 1.10 and earlier have unknown impact and at
Multiple unspecified vulnerabilities in Neocrome Seditio 1.10 and earlier have unknown impact and attack vectors related to (1) plugins/ipsearch/ipsearch.admin.php, and (2) pfs/pfs.edit.inc.php, (3) users/users.register.inc.php in system/core. NOTE: the users.profile.inc.php vector is identified by CVE-2006-6177. NOTE: these issues might be related to SQL injec
nvd
CVE-2006-2634P4MEDIUMCVSS 4.3v1022006-05-30
CVE-2006-2634 [MEDIUM] CVE-2006-2634: Cross-site scripting (XSS) vulnerability in Neocrome Land Down Under (LDU) in Neocrome Seditio 102 a
Cross-site scripting (XSS) vulnerability in Neocrome Land Down Under (LDU) in Neocrome Seditio 102 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer field.
nvd