Skip to main content

Vendor/product archive

jetbox / jetbox_cms CVEs

Beta · best-effort

19 CVEs tagged to jetbox / jetbox_cms0 Critical, 8 High, 10 Medium, 1 Low, 0 Unrated.

CVE-2008-6174

Published Feb 19, 2009

Cross-site scripting (XSS) vulnerability in admin/postlister/index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the liste parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4651

Published Oct 22, 2008

Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php a…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2686

Published May 22, 2007

Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter in a sendpwd task.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2684

Published May 21, 2007

Jetbox CMS 2.1 allows remote attackers to obtain sensitive information via (1) a direct request to (a) main_page.php, (b) open_tree.php, and (c) outputs.php; (2) a malformed view…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2685

Published May 21, 2007

Multiple SQL injection vulnerabilities in index.php in Jetbox CMS 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) login parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1898

Published May 16, 2007

formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.

CVSS 5.8 · Medium

CVE-2007-2731

Published May 16, 2007

CRLF injection vulnerability in formmail.php in Jetbox CMS 2.1 might allow remote attackers to inject arbitrary e-mail headers via LF (%0A) sequences in the subject parameter, a r…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2732

Published May 16, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1) path parameter to view/search/; or the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2733

Published May 16, 2007

Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts via unspecified vectors, which can be acc…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4737

Published Sep 13, 2006

SQL injection vulnerability in index.php in Jetbox CMS allows remote attackers to inject arbitrary web script or HTML via the item parameter. NOTE: The view vector is already cov…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4738

Published Sep 13, 2006

PHP remote file inclusion vulnerability in phpthumb.php in Jetbox CMS allows remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter. NOTE: The re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4739

Published Sep 13, 2006

Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the OriginalImageData paramete…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4740

Published Sep 13, 2006

Jetbox CMS allows remote attackers to obtain sensitive information via a direct request for certain files, which reveal the path in an error message.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4422

Published Aug 29, 2006

PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the relati…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3583

Published Aug 8, 2006

Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator section.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3584

Published Aug 8, 2006

Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables via URL parameters, which are evaluated a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3585

Published Aug 8, 2006

Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS 2.1 SR1 allow remote attackers to inject arbitrary web script or HTML via the (1) login parameter in admin/cms/in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3586

Published Aug 8, 2006

SQL injection vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to execute arbitrary SQL commands via the (1) frontsession COOKIE parameter and (2) view parameter in ind…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2270

Published May 9, 2006

PHP remote file inclusion vulnerability in includes/config.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary code via a URL in the relative_script_path parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1