Skip to main content

Vendor archive

crux_software CVEs

Beta · best-effort

3 CVEs tagged to vendor crux_software0 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2008-4484

Published Oct 8, 2008

main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstrated via index.php.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4483

Published Oct 8, 2008

Directory traversal vulnerability in index.php in Crux Gallery 1.32 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0700

Published Feb 12, 2008

Cross-site scripting (XSS) vulnerability in search.php in Crux Software CruxCMS 3.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE:…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1