Skip to main content

Vendor archive

kasseler-cms CVEs

Beta · best-effort

9 CVEs tagged to vendor kasseler-cms0 Critical, 2 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2013-3729

Published Mar 13, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in Kasseler CMS before 2 r1232 allow remote attackers to hijack the authentication of administrators for requests that c…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3728

Published Mar 13, 2014

Cross-site scripting (XSS) vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users with permissions to create categories to inject arbitrary web script or H…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-3727

Published Mar 13, 2014

SQL injection vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users to execute arbitrary SQL commands via the groups[] parameter to admin.php. NOTE: this…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4822

Published Apr 27, 2010

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) do, (2) id, and (3…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2229

Published Jun 26, 2009

Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter during a downlo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2228

Published Jun 26, 2009

Cross-site scripting (XSS) vulnerability in engine.php in Kasseler CMS allows remote attackers to inject arbitrary web script or HTML via the url parameter in a redirect action.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4356

Published Sep 30, 2008

Multiple SQL injection vulnerabilities in Kasseler CMS 1.1.0 and 1.2.0 allow remote attackers to execute arbitrary SQL commands via (1) the nid parameter to index.php in a View ac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3087

Published Jul 9, 2008

Directory traversal vulnerability in Kasseler CMS 1.3.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to index.php, possibly related to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3088

Published Jul 9, 2008

Cross-site scripting (XSS) vulnerability in the Files module in Kasseler CMS 1.3.0 and 1.3.1 Lite allows remote attackers to inject arbitrary web script or HTML via the cid parame…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1