Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Pragyan Cms Project Subscribe
Filtered by product Pragyan Cms
Total 6 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-1480 1 Pragyan Cms Project 1 Pragyan Cms 2018-10-10 7.5 HIGH N/A
SQL injection vulnerability in index.php Pragyan CMS 2.6.4 allows remote attackers to execute arbitrary SQL commands via the fileget parameter in a view action and other unspecified vectors.
CVE-2017-14601 1 Pragyan Cms Project 1 Pragyan Cms 2017-09-22 4.0 MEDIUM 4.9 MEDIUM
Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure.
CVE-2017-14600 1 Pragyan Cms Project 1 Pragyan Cms 2017-09-22 4.0 MEDIUM 4.9 MEDIUM
Pragyan CMS v3.0 is vulnerable to an Error-Based SQL injection in cms/admin.lib.php via $_GET['del_black'], resulting in Information Disclosure.
CVE-2015-4627 1 Pragyan Cms Project 1 Pragyan Cms 2017-09-12 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Pragyan CMS 3.0.
CVE-2015-1471 1 Pragyan Cms Project 1 Pragyan Cms 2015-02-13 7.5 HIGH N/A
SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to the default URI.
CVE-2012-6500 1 Pragyan Cms Project 1 Pragyan Cms 2013-01-22 5.0 MEDIUM N/A
Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the fileget parameter in a profile action to index.php.