RSS   Vulnerabilities for 'Anecms blog'   RSS

2010-06-24
 
CVE-2010-2437

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the comment variable to modules/blog/index.php.

 
 
CVE-2010-2436

CWE-89
 

 
SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.

 

 >>> Vendor: Anecms 2 Products
Anecms blog
Anecms


Copyright 2017, cxsecurity.com

 

Back to Top