Vulnerabilities > Fiyo > Fiyo CMS > 2.0.1.5
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-10-16 | CVE-2014-9148 | Improper Access Control vulnerability in Fiyo CMS Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur. | 9.8 |
2017-10-16 | CVE-2014-9147 | Information Exposure vulnerability in Fiyo CMS Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/. | 7.5 |