itodaro
14 exploits
Active since Apr 2018
CMS Made Simple < 2.2.7 - Authenticated Remote Code Execution via Module Import XML Package
CVSS 7.2
CMS Made Simple < 2.2.7 - Admin Password Reset via Weak Hash Comparison
CVSS 9.8
CMS Made Simple < 2.2.7 - Arbitrary File Deletion via Directory Traversal in FilePicker Module
CVSS 7.5
CMSMS <2.2.6 - Privilege Escalation
CVSS 8.8
CMS Made Simple < 2.2.6 - Remote Code Execution via Unserialize in LoginOperations
CVSS 9.8
CMS Made Simple < 2.2.7 - Authenticated Remote Code Execution via Test Function Eval Bypass
CVSS 7.2
CMS Made Simple < 2.2.7 - Authenticated Remote Code Execution via File Unpack Operation
CVSS 7.2
CMS Made Simple < 2.2.7 - Authenticated Sensitive Information Disclosure via File Rename Operation
CVSS 6.5
CMS Made Simple < 2.2.7 - Authenticated Arbitrary File Deletion via Admin Dashboard
CVSS 6.5
CMS Made Simple 2.2.7 - Privilege Escalation via Cookie eff_uid Manipulation
CVSS 8.8
CMS Made Simple < 2.2.7 - Authenticated Arbitrary File Deletion via Module Remove Operation
CVSS 6.5
CMS Made Simple < 2.2.7 - Authenticated Arbitrary File Movement via Admin Dashboard File Move Operation
CVSS 2.7
CMS Made Simple < 2.2.7 - Authenticated Sensitive Information Disclosure via File View Operation
CVSS 4.9
CMS Made Simple < 2.2.7 - Physical Path Leakage via DesignManager or FileManager Endpoints
CVSS 5.3