cbcvebase.

Kasseler-Cms Kasseler Cms vulnerabilities

5 known vulnerabilities affecting kasseler-cms/kasseler_cms.

Total CVEs
5
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2008-4356P3HIGHCVSS 7.5PoCv1.1.0v1.2.02008-09-30
CVE-2008-4356 [HIGH] CWE-89 CVE-2008-4356: Multiple SQL injection vulnerabilities in Kasseler CMS 1.1.0 and 1.2.0 allow remote attackers to exe Multiple SQL injection vulnerabilities in Kasseler CMS 1.1.0 and 1.2.0 allow remote attackers to execute arbitrary SQL commands via (1) the nid parameter to index.php in a View action to the News module; (2) the vid parameter to index.php in a Result action to the Voting module; (3) the fid parameter to index.php in a ShowForum action to the Forum module
nvd
CVE-2008-3087P4MEDIUMCVSS 5.0PoCv1.3.02008-07-09
CVE-2008-3087 [MEDIUM] CWE-22 CVE-2008-3087: Directory traversal vulnerability in Kasseler CMS 1.3.0 allows remote attackers to read arbitrary fi Directory traversal vulnerability in Kasseler CMS 1.3.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to index.php, possibly related to the phpManual module.
nvd
CVE-2009-2229P4MEDIUMCVSS 5.0PoCv1.3.52009-06-26
CVE-2009-2229 [MEDIUM] CVE-2009-2229: Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers t Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter during a download action, a different vector than CVE-2008-3087. NOTE: some of these details are obtained from third party information.
nvd
CVE-2009-4822P4MEDIUMCVSS 4.3PoCv1.3.42010-04-27
CVE-2009-4822 [MEDIUM] CWE-79 CVE-2009-4822: Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) do, (2) id, and (3) uname parameters.
nvd
CVE-2008-3088P4MEDIUMCVSS 4.3PoCv1.3.0v1.3.12008-07-09
CVE-2008-3088 [MEDIUM] CWE-79 CVE-2008-3088: Cross-site scripting (XSS) vulnerability in the Files module in Kasseler CMS 1.3.0 and 1.3.1 Lite al Cross-site scripting (XSS) vulnerability in the Files module in Kasseler CMS 1.3.0 and 1.3.1 Lite allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a Category action to index.php.
nvd
Kasseler-Cms Kasseler Cms vulnerabilities | cvebase