Tag
high
advisory
ImpressCMS 1.4.2 Remote Code Execution via Autotasks Interface (CVE-2021-47938)
2 rules 2 TTPs 1 CVEImpressCMS 1.4.2 is vulnerable to remote code execution (RCE) via the autotasks administrative interface, where authenticated attackers can inject malicious PHP code into the sat_code parameter via a POST request to /modules/system/admin.php, leading to arbitrary PHP code execution through GET parameters (CVE-2021-47938).
ImpressCMS 1.4.2
code-injection
rce
impresscms
2r
2t
1c
high
advisory
ImpressCMS 1.3.11 Time-Based Blind SQL Injection Vulnerability
2 rules 1 TTP 1 CVE 1 IOCImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability allowing authenticated attackers to manipulate database queries by injecting SQL code through the 'bid' parameter via POST requests to the admin.php endpoint.
sqli
impresscms
cve-2019-25703
2r
1t
1c
1i