Skip to main content

Vendor/product archive

setucocms_project / setucocms CVEs

Beta · best-effort

6 CVEs tagged to setucocms_project / setucocms0 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2016-4896

Published Apr 12, 2017

SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthorized information via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4895

Published Apr 12, 2017

SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4894

Published Apr 12, 2017

SetsucoCMS all versions allows remote attackers to cause a denial of service via unspecified vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4893

Published Apr 12, 2017

SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4892

Published Apr 12, 2017

Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4891

Published Apr 12, 2017

Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authentication of an administrator to change settings via unspecif…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1