Vulnerabilities > Siteframe

DATE CVE VULNERABILITY TITLE RISK
2009-07-13 CVE-2009-2443 Permissions, Privileges, and Access Controls vulnerability in Siteframe CMS 3.2.1/3.2.2/3.2.3
Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
network
low complexity
siteframe CWE-264
5.0
2008-07-22 CVE-2008-3256 SQL Injection vulnerability in Siteframe Beaumont and Siteframe CMS
SQL injection vulnerability in folder.php in Siteframe CMS 3.2.3 and earlier, and Siteframe Beaumont 5.0.5 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
siteframe CWE-89
7.5
2006-02-19 CVE-2006-0783 HTML Injection vulnerability in Siteframe Beaumont 5.0.1/5.0.1A/5.0.2
Cross-site scripting (XSS) vulnerability in page.php in in Siteframe Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject arbitrary web script or HTML via the comment_text parameter to the user comment page (/edit/Comment).
network
siteframe
4.3