Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-7402 | Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request f Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg. NVD description · AI analysis pending | 9.8 | 5% | PoC |
| — | |
| CVE-2017-7359 | Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack. Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — |