Lucene search

K

Setucocms Security Vulnerabilities

cve
cve

CVE-2016-4891

Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authentication of an administrator to change settings via unspecified vectors.

8.8CVSS

8.8AI Score

0.002EPSS

2017-04-12 10:59 PM
28
cve
cve

CVE-2016-4892

Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

6.1CVSS

6.4AI Score

0.001EPSS

2017-04-12 10:59 PM
16
cve
cve

CVE-2016-4893

SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

8.8CVSS

8.7AI Score

0.001EPSS

2017-04-12 10:59 PM
16
cve
cve

CVE-2016-4894

SetsucoCMS all versions allows remote attackers to cause a denial of service via unspecified vectors.

5.3CVSS

5.9AI Score

0.003EPSS

2017-04-12 10:59 PM
15
cve
cve

CVE-2016-4895

SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors.

8.8CVSS

8.4AI Score

0.003EPSS

2017-04-12 10:59 PM
16
cve
cve

CVE-2016-4896

SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthorized information via unspecified vectors.

6.5CVSS

6.7AI Score

0.003EPSS

2017-04-12 10:59 PM
22