CVE-2014-9433
- EPSS 0.42%
- Veröffentlicht 31.12.2014 22:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in cms/front_content.php in Contenido before 4.9.6, when advanced mod rewrite (AMR) is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) idart, (2) lang, or (3) idc...
CVE-2008-2911
- EPSS 3.64%
- Veröffentlicht 30.06.2008 18:24:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, and (3) username parameters.
CVE-2006-5380
- EPSS 1.68%
- Veröffentlicht 18.10.2006 04:06:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Remote file inclusion vulnerability in Contenido CMS allows remote attackers to execute arbitrary PHP code via a URL in the contenido_path parameter to (1) cms/dbfs.php or (2) cms/front_content.php. NOTE: CVE disputes this issue for version 4.6.15, ...
- EPSS 0.31%
- Veröffentlicht 18.10.2006 04:06:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Contenido CMS stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain database credentials and other information via a direct request to (1) db_msql.inc, (2) db_mssql.inc, (3) db_mysqli.inc, ...
CVE-2005-4132
- EPSS 0.57%
- Veröffentlicht 09.12.2005 11:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unspecified "security leak" vulnerability in Contenido before 4.6.4, when register_globals is on and allow_url_fopen is true, has unspecified impact and attack vectors. NOTE: it is likely that this is a PHP remote file include vulnerability.