Yeager Cms
Yeager · 5 CVEs
CVE-2015-7567
CRITICAL
SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "pass…
Feb 18, 2020
CVE-2015-7571
HIGH
Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploadi…
Aug 7, 2017
CVE-2015-7570
HIGH
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbo…
Apr 24, 2017
CVE-2015-7569
HIGH
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary…
Apr 24, 2017
CVE-2015-7568
CRITICAL
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the…
Apr 24, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2015-7567 | SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passwordreset&token" parameter. | CRITICAL | 3.67% | Feb 18, 2020 |
| CVE-2015-7571 | Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. | HIGH | 8.44% | Aug 7, 2017 |
| CVE-2015-7570 | Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open ports vi… | HIGH | 6.03% | Apr 24, 2017 |
| CVE-2015-7569 | SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" p… | HIGH | 2.79% | Apr 24, 2017 |
| CVE-2015-7568 | SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via t… | CRITICAL | 4.06% | Apr 24, 2017 |
Showing 1 to 5 of 5 CVEs