Contenido Contendio vulnerabilities
5 known vulnerabilities affecting contenido/contendio.
Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2LOW1
Vulnerabilities
Page 1 of 1
CVE-2008-2911P4MEDIUMCVSS 4.3PoCv4.8.42008-06-30
CVE-2008-2911 [MEDIUM] CWE-79 CVE-2008-2911: Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote att
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, and (3) username parameters.
nvd
CVE-2006-5380P4HIGHCVSS 7.5v4.6.152006-10-18
CVE-2006-5380 [HIGH] CVE-2006-5380: Remote file inclusion vulnerability in Contenido CMS allows remote attackers to execute arbitrary PH
Remote file inclusion vulnerability in Contenido CMS allows remote attackers to execute arbitrary PHP code via a URL in the contenido_path parameter to (1) cms/dbfs.php or (2) cms/front_content.php. NOTE: CVE disputes this issue for version 4.6.15, because $contenido_path is set to a static value
nvd
CVE-2006-5381P4MEDIUMCVSS 5.0v4.5.2_alphav4.5.6_beta+1 more2006-10-18
CVE-2006-5381 [MEDIUM] CVE-2006-5381: Contenido CMS stores sensitive data under the web root with insufficient access control, which allow
Contenido CMS stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain database credentials and other information via a direct request to (1) db_msql.inc, (2) db_mssql.inc, (3) db_mysqli.inc, (4) db_oci8.inc, (5) db_odbc.inc, (6) db_oracle.inc, (7) db_pgsql.inc, or (8) db_sybase.inc in the conlib/ dire
nvd
CVE-2005-4132P4HIGHCVSS 7.5v4.5.2_alphav4.5.6_beta+1 more2005-12-09
CVE-2005-4132 [HIGH] CVE-2005-4132: Unspecified "security leak" vulnerability in Contenido before 4.6.4, when register_globals is on and
Unspecified "security leak" vulnerability in Contenido before 4.6.4, when register_globals is on and allow_url_fopen is true, has unspecified impact and attack vectors. NOTE: it is likely that this is a PHP remote file include vulnerability.
nvd
CVE-2014-9433P4LOWCVSS 2.6v4.9.0v4.9.1+4 more2014-12-31
CVE-2014-9433 [LOW] CWE-79 CVE-2014-9433: Multiple cross-site scripting (XSS) vulnerabilities in cms/front_content.php in Contenido before 4.9
Multiple cross-site scripting (XSS) vulnerabilities in cms/front_content.php in Contenido before 4.9.6, when advanced mod rewrite (AMR) is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) idart, (2) lang, or (3) idcat parameter.
nvd