Vulnerabilities > Ektron > Cms4000 NET

DATE CVE VULNERABILITY TITLE RISK
2009-12-30 CVE-2009-4473 Cross-Site Scripting vulnerability in Ektron Cms4000.Net
Multiple cross-site scripting (XSS) vulnerabilities in WorkArea/ContentDesigner/ekformsiframe.aspx in Ektron CMS400.NET 7.6.1.53 and 7.6.6.47, and possibly 7.52 through 7.66sp2, allow remote attackers to inject arbitrary web script or HTML via the (1) css, (2) eca, (3) id, and (4) skin parameters.
network
ektron CWE-79
4.3
2008-11-18 CVE-2008-5122 SQL Injection vulnerability in Ektron Cms4000.Net
SQL injection vulnerability in WorkArea/ContentRatingGraph.aspx in Ektron CMS400.NET 7.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the res parameter.
network
low complexity
ektron CWE-89
7.5
2008-08-06 CVE-2008-3499 Remote Security vulnerability in Cms4000.Net
Unspecified vulnerability in "a page in the workarea folder" in Ektron CMS400.NET 7.00 through 7.04 and 7.50 through 7.52 has unknown impact and attack vectors.
network
low complexity
ektron
critical
10.0