cbcvebase.

Iss-Oberlausitz Bluepage Cms vulnerabilities

4 known vulnerabilities affecting iss-oberlausitz/bluepage_cms.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2008-6039P3MEDIUMCVSS 6.8PoCfixed in 2.5.82009-02-03
CVE-2008-6039 [MEDIUM] CWE-287 CVE-2008-6039: Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
nvd
CVE-2022-38923P3CRITICALCVSS 9.8≤ 3.92023-04-03
CVE-2022-38923 [CRITICAL] CWE-89 CVE-2022-38923: BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' field using a Time-based blind SLEEP payload.
nvd
CVE-2022-38922P3CRITICALCVSS 9.8≤ 3.92023-04-03
CVE-2022-38922 [CRITICAL] CWE-89 CVE-2022-38922: BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'users-cookie-settings' token using a Time-based blind SLEEP payload.
nvd
CVE-2008-6027P4MEDIUMCVSS 4.3fixed in 2.5.82009-02-03
CVE-2008-6027 [MEDIUM] CWE-79 CVE-2008-6027: Multiple cross-site scripting (XSS) vulnerabilities in index.php in BLUEPAGE CMS 2.5 and earlier all Multiple cross-site scripting (XSS) vulnerabilities in index.php in BLUEPAGE CMS 2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) whl, (2) var_1, and (3) search parameters.
nvd
Iss-Oberlausitz Bluepage Cms vulnerabilities | cvebase