Skip to main content

Vendor/product archive

tincan / webbler_cms CVEs

Beta · best-effort

3 CVEs tagged to tincan / webbler_cms0 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2007-4071

Published Jul 30, 2007

Multiple cross-site scripting (XSS) vulnerabilities in uploader/index.php in Webbler CMS before 3.1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) pag…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4072

Published Jul 30, 2007

Webbler CMS before 3.1.6 provides the full installation path within HTML comments in certain documents, which allows remote attackers to obtain sensitive information by viewing th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4073

Published Jul 30, 2007

Webbler CMS before 3.1.6 does not properly restrict use of "mail a friend" forms, which allows remote attackers to send arbitrary amounts of forged e-mail. NOTE: this could be le…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1