CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1).
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.
Traq 3.7.1 allows SQL Injection via a tickets?search= URI.
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows XSS by creating a new file containing a crafted attribute of an IMG element.
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit/1 Body field.
Frog CMS 0.9.5 provides a directory listing for a /public request.
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI.
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit/1 Body field.
