Lucidcrew / Pixie
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2017-7402 | Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request… | CRITICAL | 9.8 | Apr 3, 2017 |
| CVE-2017-7363 | Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack. | MEDIUM | 6.1 | Mar 31, 2017 |
| CVE-2017-7362 | Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack. | MEDIUM | 6.1 | Mar 31, 2017 |
| CVE-2017-7361 | Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack. | MEDIUM | 6.1 | Mar 31, 2017 |
| CVE-2017-7360 | Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack. | MEDIUM | 6.1 | Mar 31, 2017 |
| CVE-2017-7359 | Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack. | MEDIUM | 6.1 | Mar 31, 2017 |
| CVE-2014-3786 | Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitr… | MEDIUM | 4.3 | Jun 4, 2014 |
| CVE-2011-4710 | Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter… | HIGH | 7.5 | Dec 8, 2011 |
| CVE-2011-3793 | Pixie 1.04 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message… | MEDIUM | 5.0 | Sep 24, 2011 |
Showing 1 to 9 of 9 CVEs