Skip to main content

Vendor/product archive

basic-cms / sweetrice CVEs

Beta · best-effort

6 CVEs tagged to basic-cms / sweetrice0 Critical, 2 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2010-5318

Published Jan 3, 2015

The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrator's password by specifying the administrator's e-mail…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5317

Published Jan 3, 2015

Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before 0.6.7.1 allow remote attackers to execute arbitrary SQL commands via (1) the file_name parameter in an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5316

Published Jan 3, 2015

Cross-site scripting (XSS) vulnerability in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to inject arbitrary web script or HTML via a top_height cookie.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3804

Published Sep 24, 2011

SweetRice 0.7.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4231

Published Dec 8, 2009

Directory traversal vulnerability in as/lib/plugins.php in SweetRice 0.5.3 and earlier allows remote attackers to include and execute arbitrary local files via .. (dot dot) in the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4224

Published Dec 7, 2009

Multiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_dir parameter…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1