Skip to main content

Vendor/product archive

tilde_cms_project / tilde_cms CVEs

Beta · best-effort

4 CVEs tagged to tilde_cms_project / tilde_cms1 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2017-11327

Published Jul 24, 2017

An issue was discovered in Tilde CMS 1.0.1. It is possible to retrieve sensitive data by using direct references. A low-privileged user can load PHP resources such as admin/conten…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11326

Published Jul 24, 2017

An issue was discovered in Tilde CMS 1.0.1. It is possible to bypass the implemented restrictions on arbitrary file upload via a filename.+php manipulation.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11325

Published Jul 24, 2017

An issue was discovered in Tilde CMS 1.0.1. Arbitrary files can be read via a file=../ attack on actionphp/download.File.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11324

Published Jul 24, 2017

An issue was discovered in Tilde CMS 1.0.1. Due to missing escaping of the backtick character, a SELECT query in class.SystemAction.php is vulnerable to SQL Injection. The vulnera…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1