Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: languages Tag: fiyo-cms Clear
ID Title
CVE-2017-17104 Information Disclosure in fiyo (CVE-2017-17104)
vulnerability in fiyo (CVE-2017-17104). Confidential information can be exposed externally.
CVE-2017-17103 SQL Injection in sqli (CVE-2017-17103)
SQL injection in sqli (CVE-2017-17103). Successful exploitation can lead to full system takeover.
CVE-2017-17102 Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].
Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].
CVE-2015-3934 SQL Injection in sqli (CVE-2015-3934)
SQL injection in sqli (CVE-2015-3934). Successful exploitation can lead to full system takeover.
CVE-2017-13778 Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the site_name parameter.
Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the site_name parameter.
CVE-2017-11631 dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.
dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.
CVE-2017-11630 Path Traversal in path-traversal (CVE-2017-11630)
path traversal in path-traversal (CVE-2017-11630). Data can be tampered with by attackers.
CVE-2017-11418 SQL Injection in sqli (CVE-2017-11418)
SQL injection in sqli (CVE-2017-11418). Successful exploitation can lead to full system takeover.
CVE-2017-11419 SQL Injection in sqli (CVE-2017-11419)
SQL injection in sqli (CVE-2017-11419). Successful exploitation can lead to full system takeover.
CVE-2017-11417 SQL Injection in sqli (CVE-2017-11417)
SQL injection in sqli (CVE-2017-11417). Successful exploitation can lead to full system takeover.
CVE-2017-11416 Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.
Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.
CVE-2017-11415 SQL Injection in sqli (CVE-2017-11415)
SQL injection in sqli (CVE-2017-11415). Successful exploitation can lead to full system takeover.
CVE-2017-11414 SQL Injection in sqli (CVE-2017-11414)
SQL injection in sqli (CVE-2017-11414). Successful exploitation can lead to full system takeover.
CVE-2017-11413 SQL Injection in sqli (CVE-2017-11413)
SQL injection in sqli (CVE-2017-11413). Successful exploitation can lead to full system takeover.
CVE-2017-11412 SQL Injection in sqli (CVE-2017-11412)
SQL injection in sqli (CVE-2017-11412). Successful exploitation can lead to full system takeover.
CVE-2017-11354 SQL Injection in sqli (CVE-2017-11354)
SQL injection in sqli (CVE-2017-11354). Successful exploitation can lead to full system takeover.
CVE-2017-8853 Path Traversal in path-traversal (CVE-2017-8853)
path traversal in path-traversal (CVE-2017-8853). Data can be tampered with by attackers.
CVE-2017-7625 Code Injection in fiyo (CVE-2017-7625)
code injection in fiyo (CVE-2017-7625). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →