RSS   Vulnerabilities for 'Travelsized cms'   RSS

2008-03-13
 
CVE-2008-1324

CWE-22
 

 
Multiple directory traversal vulnerabilities in index.php in Travelsized CMS 0.4.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page_id and (2) language parameters. NOTE: this might be the same issue as CVE-2008-1325.

 
2006-11-21
 
CVE-2006-6037

CWE-79
 

 
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dan Jensen Travelsized CMS 0.4.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) page, (2) page_id, or (3) language parameter.

 


Copyright 2024, cxsecurity.com

 

Back to Top