4.7
CVE-2016-2784
- EPSS 6.09%
- Veröffentlicht 26.05.2016 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cmsmadesimple ≫ Cms Made Simple Version1.0
Cmsmadesimple ≫ Cms Made Simple Version1.0.1
Cmsmadesimple ≫ Cms Made Simple Version1.0.2
Cmsmadesimple ≫ Cms Made Simple Version1.0.3
Cmsmadesimple ≫ Cms Made Simple Version1.0.4
Cmsmadesimple ≫ Cms Made Simple Version1.0.5
Cmsmadesimple ≫ Cms Made Simple Version1.0.6
Cmsmadesimple ≫ Cms Made Simple Version1.0.7
Cmsmadesimple ≫ Cms Made Simple Version1.0.8
Cmsmadesimple ≫ Cms Made Simple Version1.1
Cmsmadesimple ≫ Cms Made Simple Version1.1.1
Cmsmadesimple ≫ Cms Made Simple Version1.1.2
Cmsmadesimple ≫ Cms Made Simple Version1.1.3.1
Cmsmadesimple ≫ Cms Made Simple Version1.1.4.1
Cmsmadesimple ≫ Cms Made Simple Version1.2
Cmsmadesimple ≫ Cms Made Simple Version1.2.1
Cmsmadesimple ≫ Cms Made Simple Version1.2.2
Cmsmadesimple ≫ Cms Made Simple Version1.2.3
Cmsmadesimple ≫ Cms Made Simple Version1.2.4
Cmsmadesimple ≫ Cms Made Simple Version1.2.5
Cmsmadesimple ≫ Cms Made Simple Version1.3
Cmsmadesimple ≫ Cms Made Simple Version1.3.1
Cmsmadesimple ≫ Cms Made Simple Version1.4
Cmsmadesimple ≫ Cms Made Simple Version1.4.1
Cmsmadesimple ≫ Cms Made Simple Version1.5
Cmsmadesimple ≫ Cms Made Simple Version1.5.1
Cmsmadesimple ≫ Cms Made Simple Version1.5.2
Cmsmadesimple ≫ Cms Made Simple Version1.5.3
Cmsmadesimple ≫ Cms Made Simple Version1.5.4
Cmsmadesimple ≫ Cms Made Simple Version1.6
Cmsmadesimple ≫ Cms Made Simple Version1.6.1
Cmsmadesimple ≫ Cms Made Simple Version1.6.2
Cmsmadesimple ≫ Cms Made Simple Version1.6.3
Cmsmadesimple ≫ Cms Made Simple Version1.6.4
Cmsmadesimple ≫ Cms Made Simple Version1.6.5
Cmsmadesimple ≫ Cms Made Simple Version1.6.6
Cmsmadesimple ≫ Cms Made Simple Version1.6.7
Cmsmadesimple ≫ Cms Made Simple Version1.6.8
Cmsmadesimple ≫ Cms Made Simple Version1.6.9
Cmsmadesimple ≫ Cms Made Simple Version1.6.10
Cmsmadesimple ≫ Cms Made Simple Version1.7
Cmsmadesimple ≫ Cms Made Simple Version1.7.1
Cmsmadesimple ≫ Cms Made Simple Version1.8
Cmsmadesimple ≫ Cms Made Simple Version1.8.1
Cmsmadesimple ≫ Cms Made Simple Version1.8.2
Cmsmadesimple ≫ Cms Made Simple Version1.9
Cmsmadesimple ≫ Cms Made Simple Version1.9.1
Cmsmadesimple ≫ Cms Made Simple Version1.9.2
Cmsmadesimple ≫ Cms Made Simple Version1.9.3
Cmsmadesimple ≫ Cms Made Simple Version1.9.4
Cmsmadesimple ≫ Cms Made Simple Version1.9.4.1
Cmsmadesimple ≫ Cms Made Simple Version1.9.4.2
Cmsmadesimple ≫ Cms Made Simple Version1.9.4.3
Cmsmadesimple ≫ Cms Made Simple Version1.10
Cmsmadesimple ≫ Cms Made Simple Version1.10.1
Cmsmadesimple ≫ Cms Made Simple Version1.10.2
Cmsmadesimple ≫ Cms Made Simple Version1.10.3
Cmsmadesimple ≫ Cms Made Simple Version1.11
Cmsmadesimple ≫ Cms Made Simple Version1.11.1
Cmsmadesimple ≫ Cms Made Simple Version1.11.2
Cmsmadesimple ≫ Cms Made Simple Version1.11.2.1
Cmsmadesimple ≫ Cms Made Simple Version1.11.3
Cmsmadesimple ≫ Cms Made Simple Version1.11.4
Cmsmadesimple ≫ Cms Made Simple Version1.11.5
Cmsmadesimple ≫ Cms Made Simple Version1.11.6
Cmsmadesimple ≫ Cms Made Simple Version1.11.7
Cmsmadesimple ≫ Cms Made Simple Version1.11.8
Cmsmadesimple ≫ Cms Made Simple Version1.11.9
Cmsmadesimple ≫ Cms Made Simple Version1.11.10
Cmsmadesimple ≫ Cms Made Simple Version1.11.11
Cmsmadesimple ≫ Cms Made Simple Version1.11.12
Cmsmadesimple ≫ Cms Made Simple Version1.11.13
Cmsmadesimple ≫ Cms Made Simple Version1.12
Cmsmadesimple ≫ Cms Made Simple Version1.12.1
Cmsmadesimple ≫ Cms Made Simple Version2.0
Cmsmadesimple ≫ Cms Made Simple Version2.0.1
Cmsmadesimple ≫ Cms Made Simple Version2.0.1.1
Cmsmadesimple ≫ Cms Made Simple Version2.1
Cmsmadesimple ≫ Cms Made Simple Version2.1.1
Cmsmadesimple ≫ Cms Made Simple Version2.1.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.09% | 0.898 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.7 | 1.6 | 2.7 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.