Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Tilde Cms Project Subscribe
Filtered by product Tilde Cms
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-11326 1 Tilde Cms Project 1 Tilde Cms 2019-10-02 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Tilde CMS 1.0.1. It is possible to bypass the implemented restrictions on arbitrary file upload via a filename.+php manipulation.
CVE-2017-11325 1 Tilde Cms Project 1 Tilde Cms 2017-07-31 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Tilde CMS 1.0.1. Arbitrary files can be read via a file=../ attack on actionphp/download.File.php.
CVE-2017-11324 1 Tilde Cms Project 1 Tilde Cms 2017-07-28 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Tilde CMS 1.0.1. Due to missing escaping of the backtick character, a SELECT query in class.SystemAction.php is vulnerable to SQL Injection. The vulnerability can be triggered via a POST request to /actionphp/action.input.php with the id parameter.
CVE-2017-11327 1 Tilde Cms Project 1 Tilde Cms 2017-07-28 4.0 MEDIUM 6.5 MEDIUM
An issue was discovered in Tilde CMS 1.0.1. It is possible to retrieve sensitive data by using direct references. A low-privileged user can load PHP resources such as admin/content.php and admin/content.php?method=ftp_upload.