chivato

Results 5 issues of chivato

### Summary An authenticated user can use a path traversal attack (`../`) in the site settings page to include and run PHP files that exist outside of the webroot. ###...

A reflected XSS vulnerability exists in /hashtag/hashtag.php here (lines 19-21): ``` | Wallstant ``` An example URL to exploit said reflected XSS would be: - http://localhost/hashtag/hashtag.php?tag=%3C/title%3E%3Cscript%3Ealert();%3C/script%3E ![Screenshot from 2020-10-03 21-20-59](https://user-images.githubusercontent.com/61525295/95001058-5ac95080-05be-11eb-90aa-6288985a7eb3.png)...

# Summary In the latest version of SiberianCMS, there is a massive lack of AntiCSRF tokens on the system administration site. Due to this, a malicious attacker can formulate a...

bug

Add more years