Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-16450PUBLISHED: 2018-09-04CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.
CVE-2018-16444PUBLISHED: 2018-09-04An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.
CVE-2018-16445PUBLISHED: 2018-09-04An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request.
CVE-2018-16446PUBLISHED: 2018-09-04An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be reinstalled by deleting install_lock.txt.
CVE-2018-16447PUBLISHED: 2018-09-04Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.