Fuel CMS version 1.4.8 suffers from an authenticated remote SQL injection vulnerability.
CMS Made Simple version 2.2.14 suffers from an authenticated remote shell upload vulnerability.
https://www.dft.go.th/laZy.txt notified by laZy hAcker
Mara CMS 7.5 – Remote Code Execution (Authenticated)
moziloCMS 2.0 – Persistent Cross-Site Scripting (Authenticated)
CMS Made Simple 2.2.14 – Arbitrary File Upload (Authenticated)
Mara CMS 7.5 – Reflective Cross-Site Scripting
BlazeDVD 7.0 Professional – ‘.plf’ Local Buffer Overflow (SEH,ASLR,DEP)
Fuel CMS 1.4.8 – ‘fuel_replace_id’ SQL Injection (Authenticated)