Vulnerabilities > Sips

DATE CVE VULNERABILITY TITLE RISK
2006-09-13 CVE-2006-4733 Remote File Include vulnerability in SIPS Box.Inc.PHP
PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) 0.3.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the config[sipssys] parameter.
network
low complexity
sips
7.5
2003-12-31 CVE-2003-1553 Information Exposure vulnerability in Sips 0.2.2
Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.
network
sips CWE-200
4.3
2002-12-31 CVE-2002-2218 Remote Security vulnerability in SIPS
CRLF injection vulnerability in the setUserValue function in sipssys/code/site.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) before 20020209 has unknown impact, possibly gaining privileges or modifying critical configuration, via a CRLF sequence in a key value.
network
low complexity
sips
critical
10.0
2002-05-29 CVE-2002-0267 Unspecified vulnerability in Sips
preferences.php in Simple Internet Publishing System (SIPS) before 0.3.1 allows remote attackers to gain administrative privileges via a linebreak in the "theme" field followed by the Status::admin command, which causes the Status line to be entered into the password file.
network
low complexity
sips
critical
10.0
2000-12-31 CVE-2000-1241 Unspecified vulnerability in Sips
Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impact and attack vectors, related to a "grave security fault."
network
low complexity
sips
critical
10.0