Skip to content
Noroxi

basic-cms records

8 published records for vendor basic-cms.

All records

8 records
  • CVE-2008-2789
    37Monitor

    SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands via the page_id parame

    HighCVSS 7.5WeaponizedEPSS 23%

    basic-cms · basic-cmsJun 20, 2008

  • CVE-2009-4231
    31Monitor

    Directory traversal vulnerability in as/lib/plugins.php in SweetRice 0.5.3 and earlier allows remote attackers to include and execute arbitr

    HighCVSS 7.5Proof of conceptEPSS 2%

    basic-cms · sweetriceDec 8, 2009

  • CVE-2010-5317
    30Monitor

    Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before 0.6.7.1 allow remote attackers to execute arbitrary SQL commands

    HighCVSS 7.5Proof of conceptEPSS 1%

    basic-cms · sweetriceJan 3, 2015

  • CVE-2009-4224
    28Monitor

    Multiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to execute arbitrary PHP co

    MediumCVSS 6.8Proof of conceptEPSS 3%

    basic-cms · sweetriceDec 7, 2009

  • CVE-2011-3804
    20Monitor

    SweetRice 0.7.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation

    MediumCVSS 5.0No exploitEPSS 1%

    basic-cms · sweetriceSep 23, 2011

  • CVE-2010-5318
    18Monitor

    The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrator's password by

    MediumCVSS 4.3Proof of conceptEPSS 2%

    basic-cms · sweetriceJan 3, 2015

  • CVE-2010-0695
    17Monitor

    Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via

    MediumCVSS 4.3Proof of conceptEPSS 1%

    basic-cms · basic-cmsFeb 23, 2010

  • CVE-2010-5316
    17Monitor

    Cross-site scripting (XSS) vulnerability in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to inject arbitrary web scr

    MediumCVSS 4.3No exploitEPSS 1%

    basic-cms · sweetriceJan 3, 2015