Vulnerabilities > XHP > CMS

DATE CVE VULNERABILITY TITLE RISK
2006-03-23 CVE-2006-1371 Code Injection vulnerability in XHP CMS
Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea FileManager plugin to upload and execute arbitrary PHP files using (1) manager.php, (2) standalonemanager.php, and (3) images.php.
network
low complexity
xhp CWE-94
critical
9.0