CVE-2009-4121
- EPSS 0.65%
- Veröffentlicht 01.12.2009 02:30:00
- Zuletzt bearbeitet 16.06.2026 23:13:04
Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.CMS 2.4 and Quick.CMS.Lite 2.4 allow remote attackers to hijack the authentication of the administrator for requests that (1) delete web pages via a p-delete action to admin.php, and...
CVE-2009-1410
- EPSS 0.99%
- Veröffentlicht 24.04.2009 14:30:00
- Zuletzt bearbeitet 16.06.2026 23:07:12
SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4139
- EPSS 1.52%
- Veröffentlicht 24.09.2008 05:41:38
- Zuletzt bearbeitet 16.06.2026 22:57:15
Cross-site scripting (XSS) vulnerability in admin.php in OpenSolution Quick.Cms.Lite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query string.
- EPSS 2.27%
- Veröffentlicht 10.11.2006 01:07:00
- Zuletzt bearbeitet 16.06.2026 22:31:58
Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the sLanguage Cookie parameter.