Vulnerabilities
Vulnerable Software
Mozilo:  >> Mozilocms  >> 2.0  Security Vulnerabilities
An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file execution or storage of malicious content.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-04-22
Cross-Site Scripting vulnerability in moziloCMS version 2.0. By sending a POST request to the '/install.php' endpoint, a JavaScript payload could be executed in the 'username' parameter.
CVSS Score
5.4
EPSS Score
0.002
Published
2024-03-07
mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.
CVSS Score
9.1
EPSS Score
0.08
Published
2022-02-03
A stored cross site scripting (XSS) vulnerability in moziloCMS 2.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Content" parameter.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-07-09


Contact Us

Shodan ® - All rights reserved