Skip to main content

Vendor/product archive

xrms / xrms_crm CVEs

Beta · best-effort

5 CVEs tagged to xrms / xrms_crm0 Critical, 1 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2008-3664

Published Sep 5, 2008

Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTML via (1) the real name field, related to the user list; (2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3948

Published Sep 5, 2008

SQL injection vulnerability in admin/users/self-2.php in XRMS allows remote attackers to execute arbitrary SQL commands and modify name and email fields via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3398

Published Jul 31, 2008

Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to unspecified component…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-3399

Published Jul 31, 2008

PHP remote file inclusion vulnerability in activities/workflow-activities.php in XRMS CRM 1.99.2, when register_globals is enabled, allows remote attackers to execute arbitrary PH…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3400

Published Jul 31, 2008

XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, which calls the phpinfo function.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1