Vulnerabilities > Cherry Design

DATE CVE VULNERABILITY TITLE RISK
2015-01-01 CVE-2011-5311 Cross-Site Request Forgery (CSRF) vulnerability in Cherry-Design Wikipad 1.6.0
Cross-site request forgery (CSRF) vulnerability in pages.php in Wikipad 1.6.0 allows remote attackers to hijack the authentication of administrators for requests that modify pages via the data[text] parameter.
6.8
2015-01-01 CVE-2011-5310 Path Traversal vulnerability in Cherry-Design Wikipad 1.6.0
Directory traversal vulnerability in pages.php in Wikipad 1.6.0 allows remote attackers to read arbitrary files via a ..
network
low complexity
cherry-design CWE-22
5.0
2015-01-01 CVE-2011-5309 Cross-site Scripting vulnerability in Cherry-Design Wikipad 1.6.0
Cross-site scripting (XSS) vulnerability in pages.php in Wikipad 1.6.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
4.3