Vulnerabilities > Onethird

DATE CVE VULNERABILITY TITLE RISK
2020-10-20 CVE-2020-5640 Unspecified vulnerability in Onethird 1.96C
Local file inclusion vulnerability in OneThird CMS v1.96c and earlier allows a remote unauthenticated attacker to execute arbitrary code or obtain sensitive information via unspecified vectors.
network
low complexity
onethird
critical
9.8
2017-04-28 CVE-2017-2124 Cross-site Scripting vulnerability in Onethird CMS
Cross-site scripting vulnerability in OneThird CMS v1.73 Heaven's Door and earlier allows remote attackers to inject arbitrary web script or HTML via contact.php.
network
low complexity
onethird CWE-79
6.1
2017-04-28 CVE-2017-2123 Cross-site Scripting vulnerability in Onethird CMS
Cross-site scripting vulnerability in OneThird CMS v1.73 Heaven's Door and earlier allows remote attackers to inject arbitrary web script or HTML via language.php.
network
low complexity
onethird CWE-79
6.1