Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2013-4900

Disclosure Date: September 09, 2013 (last updated October 05, 2023)
Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote attackers to read arbitrary files via a ..%5c (dot dot encoded backslash) in a GET request.
0
Attacker Value
Unknown

CVE-2013-4899

Disclosure Date: September 09, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Twilight CMS 5.17 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the gallery/ page.
0
Attacker Value
Unknown

CVE-2009-3856

Disclosure Date: November 04, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the default URI in news/ in Twilight CMS before 4.1 allows remote attackers to inject arbitrary web script or HTML via the calendar parameter. NOTE: some of these details are obtained from third party information.
0