Vulnerabilities (CVE)

Filtered by vendor Anchorcms Subscribe
Filtered by product Anchor Cms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-5687 1 Anchorcms 1 Anchor Cms 2015-10-06 7.5 HIGH N/A
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.
CVE-2014-9182 1 Anchorcms 1 Anchor Cms 2014-12-03 4.3 MEDIUM N/A
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.