Vulnerabilities
Vulnerable Software
Fiyo:  >> Fiyo Cms  >> 2.0.7  Security Vulnerabilities
Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-10-21
Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].
CVSS Score
7.5
EPSS Score
0.002
Published
2017-12-04
Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.
CVSS Score
8.8
EPSS Score
0.002
Published
2017-12-04
Fiyo CMS 2.0.7 has an arbitrary file read vulnerability in dapur/apps/app_theme/libs/check_file.php via $_GET['src'] or $_GET['name'].
CVSS Score
7.5
EPSS Score
0.004
Published
2017-12-04
Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the site_name parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-08-30
dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter in a type=database request, a different vulnerability than CVE-2017-8853.
CVSS Score
7.5
EPSS Score
0.008
Published
2017-07-26
dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.
CVSS Score
9.8
EPSS Score
0.002
Published
2017-07-26
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/controller/comment_status.php via $_GET['id'].
CVSS Score
9.8
EPSS Score
0.002
Published
2017-07-18
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/comment_status.php via $_GET['id'].
CVSS Score
9.8
EPSS Score
0.002
Published
2017-07-18
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/sys_comment.php via $_POST['comment'], $_POST['name'], $_POST['web'], $_POST['email'], $_POST['status'], $_POST['id'], and $_REQUEST['id'].
CVSS Score
9.8
EPSS Score
0.002
Published
2017-07-18


Contact Us

Shodan ® - All rights reserved