Vulnerabilities
Vulnerable Software
Emlog:  >> Emlog  Security Vulnerabilities
An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement and query server sensitive data via admin/navbar.php?action=add_page.
CVSS Score
8.8
EPSS Score
0.002
Published
2021-05-24
Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script as a link to a new blog post.
CVSS Score
6.1
EPSS Score
0.004
Published
2021-05-17
emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
CVSS Score
9.8
EPSS Score
0.228
Published
2021-05-06
Cross Site Scripting (XSS) vulnerability in the article comments feature in emlog 6.0.
CVSS Score
6.1
EPSS Score
0.002
Published
2021-04-29
Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.
CVSS Score
9.8
EPSS Score
0.13
Published
2021-04-02
emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.
CVSS Score
5.3
EPSS Score
0.341
Published
2021-02-08
emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.
CVSS Score
6.5
EPSS Score
0.003
Published
2019-10-01
emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal sequences in the bak[] parameter.
CVSS Score
9.8
EPSS Score
0.028
Published
2019-09-25
emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-10-15


Contact Us

Shodan ® - All rights reserved