Vulnerabilities (CVE)

Filtered by vendor Idreamsoft Subscribe
Filtered by product Icms
Total 28 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-8902 1 Idreamsoft 1 Icms 2023-12-10 4.9 MEDIUM 5.7 MEDIUM
An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.
CVE-2018-16320 1 Idreamsoft 1 Icms 2023-12-10 6.5 MEDIUM 7.2 HIGH
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file.
CVE-2019-7236 1 Idreamsoft 1 Icms 2023-12-10 5.0 MEDIUM 7.5 HIGH
An issue was discovered in idreamsoft iCMS 7.0.13. editor/editor.admincp.php allows admincp.php?app=editor&do=fileManager dir=../ Directory Traversal.
CVE-2018-16332 1 Idreamsoft 1 Icms 2023-12-10 6.8 MEDIUM 8.8 HIGH
An issue was discovered in iCMS 7.0.9. There is an admincp.php?app=article&do=update CSRF vulnerability.
CVE-2019-7234 1 Idreamsoft 1 Icms 2023-12-10 6.4 MEDIUM 9.1 CRITICAL
An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to begin the process of creating a ZIP archive file with the complete contents of any directory because of an apps.admincp.php error. This ZIP archive file can then be downloaded via an admincp.php?app=apps&do=pack request.
CVE-2019-7160 1 Idreamsoft 1 Icms 2023-12-10 7.5 HIGH 9.8 CRITICAL
idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arbitrary PHP code from a ZIP file via the admincp.php?app=apps zipfile parameter to apps.admincp.php.
CVE-2019-7237 2 Idreamsoft, Microsoft 2 Icms, Windows 2023-12-10 5.0 MEDIUM 7.5 HIGH
An issue was discovered in idreamsoft iCMS 7.0.13 on Windows. editor/editor.admincp.php allows admincp.php?app=files&do=browse ..\ Directory Traversal.
CVE-2018-13865 1 Idreamsoft 1 Icms 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in idreamsoft iCMS 7.0.9. XSS exists via the callback parameter in a public/api.php uploadpic request, bypassing the iWAF protection mechanism.