Lunax0
4 exploits
Active since Sep 2024
IceCMS < 3.4.7 - Unauthenticated Authentication Bypass via LoginAdmin Method
CVSS 7.6
IceCMS < 3.4.7 - Unauthenticated Information Disclosure via CheckVip Function
CVSS 7.5
IceCMS < 3.4.7 - Unauthenticated Arbitrary User Information Modification via UserController ChangeUser Endpoint
CVSS 7.5
icecms <= 3.4.7 - Unrestricted File Upload in FileUtils.java
CVSS 9.8