Vulnerabilities > Webcms

DATE CVE VULNERABILITY TITLE RISK
2008-09-23 CVE-2008-4186 SQL Injection vulnerability in Webcms Portal Edition
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id_doc parameter.
network
low complexity
webcms CWE-89
7.5
2008-09-23 CVE-2008-4185 SQL Injection vulnerability in Webcms Portal Edition
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter in a documentos action, a different vector than CVE-2008-3213.
network
low complexity
webcms CWE-89
7.5
2008-09-23 CVE-2008-4184 Cross-Site Scripting vulnerability in Webcms Portal Edition
Cross-site scripting (XSS) vulnerability in index.php in webCMS Portal Edition allows remote attackers to inject arbitrary web script or HTML via the patron parameter.
network
webcms CWE-79
4.3
2008-07-18 CVE-2008-3213 SQL Injection vulnerability in Webcms Portal Edition
SQL injection vulnerability in secciones/tablon/tablon.php in WebCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter to portal/index.php in a tablon action.
network
low complexity
webcms CWE-89
7.5