Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2006-4772
Disclosure Date: September 14, 2006 (last updated October 04, 2023)
HotPlug CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to read the admin password and database credentials via a direct request for includes/class/config.inc.
0
Attacker Value
Unknown
CVE-2006-3189
Disclosure Date: June 23, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
0
Attacker Value
Unknown
CVE-2006-3190
Disclosure Date: June 23, 2006 (last updated October 04, 2023)
SQL injection vulnerability in administration/includes/login/auth.php in HotPlug CMS 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.
0