Vulnerabilities > Rianxosencabos CMS

DATE CVE VULNERABILITY TITLE RISK
2009-01-30 CVE-2008-6014 SQL Injection vulnerability in Rianxosencabos CMS Rianxosencabos CMS 0.9
SQL injection vulnerability in scripts/links.php in Rianxosencabos CMS 0.9 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
rianxosencabos-cms CWE-89
7.5
2008-09-25 CVE-2008-4245 Permissions, Privileges, and Access Controls vulnerability in Rianxosencabos CMS Rianxosencabos CMS 0.9
The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a user's privileges, (2) delete a user account, or perform unspecified other administrative actions via vectors involving an admin lista action to the default URI, possibly related to useradmin.php.
network
low complexity
rianxosencabos-cms CWE-264
6.5
2008-09-25 CVE-2008-4244 Improper Authentication vulnerability in Rianxosencabos CMS Rianxosencabos CMS 0.9
Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1.
network
low complexity
rianxosencabos-cms CWE-287
7.5