Vendorsphomeempirecms6.6
Vulnerabilities

phome EmpireCMS 6.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2012-5777
Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remote attackers to execute arbitrary PHP code via a crafted template.
Published 2012-11-16 · Modified
6.8EPSS 0.022
CVE-2018-6881
EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
Published 2018-02-12 · Modified
5.3EPSS 0.022