Skip to main content

Vendor archive

elxis CVEs

Beta · best-effort

5 CVEs tagged to vendor elxis0 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2011-4918

Published Aug 29, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Elxis CMS 2009.2, 2009.3 and 2009.3 Aphrodite before revision 2684 allow remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4154

Published Dec 2, 2009

Directory traversal vulnerability in includes/feedcreator.class.php in Elxis CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4649

Published Oct 22, 2008

Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4648

Published Oct 22, 2008

Cross-site scripting (XSS) vulnerability in index.php in Elxis CMS 2008.1 revision 2204 allows remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO or the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3250

Published Jun 18, 2007

SQL injection vulnerability in mod_banners.php in Elxis CMS before 2006.4 20070613 allows remote attackers to execute arbitrary SQL commands via the mb_tracker cookie. NOTE: the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1