Vulnerabilities > Bigtreecms > Bigtree CMS

DATE CVE VULNERABILITY TITLE RISK
2017-06-02 CVE-2017-9364 Unrestricted Upload of File with Dangerous Type vulnerability in Bigtreecms Bigtree CMS
Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety check and execute any code.
network
low complexity
bigtreecms CWE-434
7.5
2017-04-15 CVE-2017-7881 Cross-Site Request Forgery (CSRF) vulnerability in Bigtreecms Bigtree CMS
BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header.
6.8
2017-04-11 CVE-2017-7695 Unrestricted Upload of File with Dangerous Type vulnerability in Bigtreecms Bigtree CMS
Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety check and execute any code.
network
low complexity
bigtreecms CWE-434
7.5
2017-03-15 CVE-2017-6918 Cross-Site Request Forgery (CSRF) vulnerability in Bigtreecms Bigtree CMS 4.2.16
CSRF exists in BigTree CMS 4.2.16 with the value[#][*] parameter to the admin/settings/update/ page.
4.3
2017-03-15 CVE-2017-6917 Cross-Site Request Forgery (CSRF) vulnerability in Bigtreecms Bigtree CMS 4.2.16
CSRF exists in BigTree CMS 4.2.16 with the value parameter to the admin/settings/update/ page.
4.3
2017-03-15 CVE-2017-6916 Cross-Site Request Forgery (CSRF) vulnerability in Bigtreecms Bigtree CMS 4.1.8
CSRF exists in BigTree CMS 4.1.18 with the nav-social[#] parameter to the admin/settings/update/ page.
4.3
2017-03-15 CVE-2017-6915 Cross-Site Request Forgery (CSRF) vulnerability in Bigtreecms Bigtree CMS 4.1.8
CSRF exists in BigTree CMS 4.1.18 with the colophon parameter to the admin/settings/update/ page.
4.3
2017-03-15 CVE-2017-6914 Cross-Site Request Forgery (CSRF) vulnerability in Bigtreecms Bigtree CMS 4.1.8/4.2.16
CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page.
5.8
2017-02-14 CVE-2016-10223 Improper Access Control vulnerability in Bigtreecms Bigtree CMS
An issue was discovered in BigTree CMS before 4.2.15.
3.5
2013-08-19 CVE-2013-5313 Cross-Site Request Forgery (CSRF) vulnerability in Bigtreecms Bigtree CMS 4.0
Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to hijack the authentication of administrators for requests that modify arbitrary user accounts via an edit user action.
6.8