VendorsPragyan CMS Projectpragyan_cmsall versions
Vulnerabilities

Pragyan CMS Project Pragyan CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2015-4627
SQL injection vulnerability in Pragyan CMS 3.0.
Published 2017-09-07 · Modified
9.8EPSS 0.010
CVE-2015-1471
SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to the default URI.
Published 2015-02-12 · Modified
7.51 PoCEPSS 0.038
CVE-2009-1480
SQL injection vulnerability in index.php Pragyan CMS 2.6.4 allows remote attackers to execute arbitrary SQL commands via the fileget parameter in a view action and other unspecified vectors.
Published 2009-04-29 · Modified
7.51 PoCEPSS 0.010
CVE-2012-6500
Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the fileget parameter in a profile action to index.php.
Published 2013-01-12 · Modified
5.01 PoCEPSS 0.034
CVE-2017-14600
Pragyan CMS v3.0 is vulnerable to an Error-Based SQL injection in cms/admin.lib.php via $_GET['del_black'], resulting in Information Disclosure.
Published 2017-09-19 · Modified
4.9EPSS 0.012
CVE-2017-14601
Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure.
Published 2017-09-19 · Modified
4.9EPSS 0.012