Vulnerabilities > Insanevisions > Onecms

DATE CVE VULNERABILITY TITLE RISK
2011-10-07 CVE-2010-4877 Cross-Site Scripting vulnerability in Insanevisions Onecms 2.6.1
Cross-site scripting (XSS) vulnerability in index.php in OneCMS 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the view parameter.
4.3
2010-03-10 CVE-2010-0952 SQL Injection vulnerability in Insanevisions Onecms 2.5
SQL injection vulnerability in index.php in OneCMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an elite action.
6.8
2009-04-07 CVE-2008-6652 SQL Injection vulnerability in Insanevisions Onecms 2.5
SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the sitename parameter.
network
low complexity
insanevisions CWE-89
7.5
2008-05-28 CVE-2008-2482 Path Traversal vulnerability in Insanevisions Onecms 2.5
Directory traversal vulnerability in install_mod.php in insanevisions OneCMS 2.5 allows remote attackers to include and execute arbitrary local files via a ..
network
low complexity
insanevisions CWE-22
7.5