Known Vulnerabilities for Gxlcms Qy by Gxlcms
Listed below are 6 of the newest known vulnerabilities associated with "Gxlcms Qy" by "Gxlcms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2018-9852 json | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by embe... | 9.8 - CRITICAL | 2018-04-08 | 2020-01-30 |
| CVE-2018-9851 json | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified path... | 7.5 - HIGH | 2018-04-08 | 2018-05-17 |
| CVE-2018-9850 json | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory tr... | 7.5 - HIGH | 2018-04-08 | 2018-05-14 |
| CVE-2018-9848 json | In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to execute... | 9.8 - CRITICAL | 2018-04-07 | 2018-05-14 |
| CVE-2018-9847 json | In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute ar... | 9.8 - CRITICAL | 2018-04-07 | 2018-05-14 |
| CVE-2018-9247 json | The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute ar... | 9.8 - CRITICAL | 2018-04-04 | 2018-05-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gxlcms | Gxlcms Qy | 1.0.0713 |