Skip to content
Noroxi

hotplug cms records

3 published records for vendor hotplug cms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

      The weakness classes this vendor ships most often: where to look.

      CWE

      All records

      3 records
      • CVE-2006-3190
        30Monitor

        SQL injection vulnerability in administration/includes/login/auth.php in HotPlug CMS 1.0 allows remote attackers to execute arbitrary SQL co

        HighCVSS 7.5No exploitEPSS 1%

        hotplug cms · hotplug cmsJun 22, 2006

      • CVE-2006-3189
        24Monitor

        Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitr

        MediumCVSS 5.8Proof of conceptEPSS 2%

        hotplug cms · hotplug cmsJun 22, 2006

      • CVE-2006-4772
        20Monitor

        HotPlug CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to read the admi

        MediumCVSS 5.0No exploitEPSS 1%

        hotplug cms · hotplug cmsSep 13, 2006