Skip to main content

Vendor/product archive

bj_sintay / sitex CVEs

Beta · best-effort

3 CVEs tagged to bj_sintay / sitex0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2007-1234

Published Mar 3, 2007

Multiple cross-site scripting (XSS) vulnerabilities in sitex allow remote attackers to inject arbitrary web script or HTML via (1) the sxYear parameter to calendar.php, (2) the se…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1235

Published Mar 3, 2007

Unrestricted file upload vulnerability in sitex allows remote attackers to upload arbitrary PHP code via an avatar filename with a double extension such as .php.jpg, which fails v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1237

Published Mar 3, 2007

sitex allows remote attackers to obtain potentially sensitive information via a ' (quote) value for certain parameters, as demonstrated by parameters used in forum and search, whi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1