Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2011-3720

Disclosure Date: September 23, 2011 (last updated October 04, 2023)
conceptcms 5.3.1, 5.3.3, and possibly other versions allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by sys_libs/umlib/um_authserver.inc.php and certain other files.
0
Attacker Value
Unknown

CVE-2010-3489

Disclosure Date: September 22, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in netautor/napro4/home/login2.php in CMS Digital Workroom (formerly Netautor Professional) 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the goback parameter.
0
Attacker Value
Unknown

CVE-2009-2163

Disclosure Date: June 22, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in login/default.aspx in Sitecore CMS before 6.0.2 Update-1 090507 allows remote attackers to inject arbitrary web script or HTML via the sc_error parameter.
0
Attacker Value
Unknown

CVE-2009-1055

Disclosure Date: March 24, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the web service in Sitecore CMS 5.3.1 rev. 071114 allows remote authenticated users to gain access to security databases, and obtain administrative and user credentials, via unknown vectors related to SOAP and XML requests.
0