cbcvebase.

Tribiq Cms vulnerabilities

7 known vulnerabilities affecting tribiq/tribiq_cms.

Total CVEs
7
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM4LOW1

Vulnerabilities

Page 1 of 1
CVE-2008-6804P3HIGHCVSS 7.5PoCv5.0.9a2009-05-11
CVE-2008-6804 [HIGH] CWE-287 CVE-2008-6804: Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative acce Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NOTE: a third party reports that the vendor disputes the existence of this issue
nvd
CVE-2009-2220P4MEDIUMCVSS 5.1PoCv5.0.12c2009-06-26
CVE-2009-2220 [MEDIUM] CVE-2009-2220: Multiple directory traversal vulnerabilities in Tribiq CMS 5.0.12c, when register_globals is enabled Multiple directory traversal vulnerabilities in Tribiq CMS 5.0.12c, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and possibly execute arbitrary files via directory traversal sequences in the template_path parameter to (1) masthead.inc.php, (2) toppanel.inc.php, and (3) contact.inc.php in templates/mytrib
nvd
CVE-2008-4894P4MEDIUMCVSS 5.1PoCv5.0.10a2008-11-04
CVE-2008-4894 [MEDIUM] CWE-22 CVE-2008-4894: Directory traversal vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php Directory traversal vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the template_path parameter. NOTE: it was later reported th
nvd
CVE-2008-5960P3HIGHCVSS 7.5v5.0.10bv5.0.11e2009-01-23
CVE-2008-5960 [HIGH] CWE-89 CVE-2008-5960: SQL injection vulnerability in index.php in Tribiq CMS Community 5.0.10B and 5.0.11E allows remote a SQL injection vulnerability in index.php in Tribiq CMS Community 5.0.10B and 5.0.11E allows remote attackers to execute arbitrary SQL commands via the cID parameter in a document action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2008-4893P4LOWCVSS 2.6PoCv5.0.10a2008-11-04
CVE-2008-4893 [LOW] CWE-79 CVE-2008-4893: Cross-site scripting (XSS) vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.i Cross-site scripting (XSS) vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the template_path parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third p
nvd
CVE-2008-5961P4MEDIUMCVSS 4.3v5.0.10bv5.0.11e2009-01-23
CVE-2008-5961 [MEDIUM] CWE-79 CVE-2008-5961: Cross-site scripting (XSS) vulnerability in index.php in Tribiq CMS Community 5.0.10B and 5.0.11E al Cross-site scripting (XSS) vulnerability in index.php in Tribiq CMS Community 5.0.10B and 5.0.11E allows remote attackers to inject arbitrary web script or HTML via the cID parameter in a document action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2011-2727P4MEDIUMCVSS 4.3≤ 5.2.7b2014-12-30
CVE-2011-2727 [MEDIUM] CWE-200 CVE-2011-2727: The (1) templatewrap/templatefoot.php, (2) cmsjs/plugin.js.php, and (3) cmsincludes/cms_plugin_api_l The (1) templatewrap/templatefoot.php, (2) cmsjs/plugin.js.php, and (3) cmsincludes/cms_plugin_api_link.inc.php scripts in Tribal Tribiq CMS before 5.2.7c allow remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.
nvd
Tribiq Cms vulnerabilities | cvebase