Zikula / Zikula Application Framework
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2014-2293 | Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or execute arbitr… | CRITICAL | 9.8 | Mar 26, 2018 |
| CVE-2016-9835 | Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launch a PHP o… | CRITICAL | 9.8 | Dec 5, 2016 |
| CVE-2013-6168 | Cross-site scripting (XSS) vulnerability in Zikula Application Framework before 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the re… | MEDIUM | 4.3 | Nov 14, 2013 |
| CVE-2011-3979 | Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Application Framework 1.3.0 bu… | MEDIUM | 4.3 | Oct 4, 2011 |
| CVE-2011-0911 | Cross-site scripting (XSS) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecif… | MEDIUM | 4.3 | Feb 8, 2011 |
| CVE-2011-0535 | Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of administrato… | MEDIUM | 6.8 | Feb 8, 2011 |
| CVE-2010-4729 | Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier for remote… | MEDIUM | 6.8 | Feb 8, 2011 |
| CVE-2010-4728 | Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protection mechani… | MEDIUM | 5.0 | Feb 8, 2011 |
| CVE-2010-1732 | Cross-site request forgery (CSRF) vulnerability in the users module in Zikula Application Framework before 1.2.3 allows remote attackers to hijack the authenti… | MEDIUM | 6.8 | May 5, 2010 |
| CVE-2010-1724 | Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web… | MEDIUM | 4.3 | May 5, 2010 |
Showing 1 to 10 of 10 CVEs