Vulnerabilities > Hotplug CMS

DATE CVE VULNERABILITY TITLE RISK
2006-09-14 CVE-2006-4772 Information Disclosure vulnerability in Hotplug Cms
HotPlug CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to read the admin password and database credentials via a direct request for includes/class/config.inc.
network
low complexity
hotplug-cms
5.0
2006-06-23 CVE-2006-3190 SQL-Injection vulnerability in Hotplug CMS Hotplug CMS 1.0
SQL injection vulnerability in administration/includes/login/auth.php in HotPlug CMS 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.
network
low complexity
hotplug-cms
7.5
2006-06-23 CVE-2006-3189 Cross-Site Scripting vulnerability in Hotplug CMS Hotplug CMS 1.0
Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
network
hotplug-cms
5.8