Skip to main content

Vendor archive

cromosoft CVEs

Beta · best-effort

4 CVEs tagged to vendor cromosoft1 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2009-4544

Published Jan 4, 2010

Cross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to inject arbitrary web script or HTML via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4543

Published Jan 4, 2010

PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute arbitrary PHP code via a URL in the lng p…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1138

Published Mar 2, 2007

Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary file…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1139

Published Mar 2, 2007

Unrestricted file upload vulnerability in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to upload arbitrary scripts via a filename with a double extension.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1