Vulnerabilities > 4Site

DATE CVE VULNERABILITY TITLE RISK
2010-11-03 CVE-2010-4152 SQL Injection vulnerability in 4Site CMS 2.0/2.2
SQL injection vulnerability in catalog/index.shtml in 4site CMS 2.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the cat parameter.
network
low complexity
4site CWE-89
7.5
2009-02-18 CVE-2009-0646 SQL Injection vulnerability in 4Site CMS
Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) password parameters to pcgi/4site.pl, (3) page parameter to print/print.shtml, (4) s and (5) i parameters to portfolio/index.shtml, (6) h parameter to hotel/index.php, (7) id parameter to news/news1.shtml, and the (8) th parameter to faq/index.shtml.
network
low complexity
4site CWE-89
7.5