Vulnerabilities > Phome > High

DATE CVE VULNERABILITY TITLE RISK
2024-01-09 CVE-2023-50162 SQL Injection vulnerability in Phome Empirecms 7.5
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.
network
low complexity
phome CWE-89
7.2
2019-06-07 CVE-2018-19462 SQL Injection vulnerability in Phome Empirecms
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.
network
low complexity
phome CWE-89
7.2
2019-03-07 CVE-2018-18449 Cross-Site Request Forgery (CSRF) vulnerability in Phome Empirecms 7.5
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.
network
low complexity
phome CWE-352
8.8
2018-10-09 CVE-2018-18086 Unrestricted Upload of File with Dangerous Type vulnerability in Phome Empirecms 7.5
EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.
network
low complexity
phome CWE-434
8.8
2018-09-02 CVE-2018-16339 Cross-Site Request Forgery (CSRF) vulnerability in Phome Empirecms 7.0
An issue was discovered in EmpireCMS 7.0.
network
low complexity
phome CWE-352
8.8