VendorsiDreamSofticms7.0.14
Vulnerabilities

iDreamSoft iCMS 7.0.14

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2020-19527
iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.
Published 2020-12-10 · Modified
10.0EPSS 0.016
CVE-2019-17552
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
Published 2019-10-14 · Modified
9.8EPSS 0.011
CVE-2019-11426
An XSS issue was discovered in app/admincp/template/admincp.header.php in idreamsoft iCMS 7.0.14 via the admincp.php?app=config tab parameter.
Published 2019-04-21 · Modified
6.1EPSS 0.008
CVE-2019-11427
An XSS issue was discovered in app/search/search.app.php in idreamsoft iCMS 7.0.14 via the public/api.php?app=search q parameter.
Published 2019-04-21 · Modified
6.1EPSS 0.008