RSS   Podatności dla 'Sitexs cms'   RSS

2009-01-30
 
CVE-2009-0371

CWE-22
 

 
Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the type parameter.

 
2009-04-06
 
CVE-2008-6617

CWE-264
 

 
Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.

 


Copyright 2024, cxsecurity.com

 

Back to Top