Vulnerabilities
Vulnerable Software
Phome:  >> Empirecms  Security Vulnerabilities
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.
CVSS Score
7.2
EPSS Score
0.009
Published
2024-01-09
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
CVSS Score
9.8
EPSS Score
0.002
Published
2022-05-03
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
CVSS Score
9.8
EPSS Score
0.03
Published
2021-08-17
admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
CVSS Score
4.8
EPSS Score
0.003
Published
2019-06-07
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.
CVSS Score
7.2
EPSS Score
0.003
Published
2019-06-07
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.
CVSS Score
6.1
EPSS Score
0.001
Published
2019-05-27
EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-05-27
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.
CVSS Score
8.8
EPSS Score
0.001
Published
2019-03-07
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
CVSS Score
9.8
EPSS Score
0.01
Published
2018-12-20
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.
CVSS Score
9.8
EPSS Score
0.038
Published
2018-10-31


Contact Us

Shodan ® - All rights reserved