Vulnerabilities > Phome > High

DATE CVE VULNERABILITY TITLE RISK
2024-01-09 CVE-2023-50162 SQL Injection vulnerability in Phome Empirecms 7.5
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.
network
low complexity
phome CWE-89
7.2
2022-05-03 CVE-2022-28585 SQL Injection vulnerability in Phome Empirecms 7.5
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
network
low complexity
phome CWE-89
7.5
2019-06-07 CVE-2018-19462 SQL Injection vulnerability in Phome Empirecms
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.
network
low complexity
phome CWE-89
7.2
2018-12-20 CVE-2018-20300 Code Injection vulnerability in Phome Empirecms 7.5
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
network
low complexity
phome CWE-94
7.5
2018-10-31 CVE-2018-18869 Path Traversal vulnerability in Phome Empirecms 7.5
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.
network
low complexity
phome CWE-22
7.5