Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2010-4616

Disclosure Date: December 29, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in modules/content/admin/content.php in ImpressCMS 1.2.3 Final, and possibly other versions before 1.2.4, allows remote attackers to inject arbitrary web script or HTML via the quicksearch_ContentContent parameter.
0
Attacker Value
Unknown

CVE-2010-4271

Disclosure Date: November 17, 2010 (last updated October 04, 2023)
SQL injection vulnerability in ImpressCMS before 1.2.3 RC2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-6360

Disclosure Date: March 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the userranks feature in modules/system/admin.php in ImpressCMS 1.0.2 final allows remote attackers to inject arbitrary web script or HTML via the rank_title parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-5964

Disclosure Date: January 23, 2009 (last updated October 04, 2023)
Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
0
Attacker Value
Unknown

CVE-2008-3453

Disclosure Date: August 04, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php and "a few files."
0