4.3
CVSSv2

CVE-2007-5304

Published: 09/10/2007 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in ELSEIF CMS Beta 0.6 allow remote malicious users to inject arbitrary web script or HTML via the (1) repertimage parameter to utilisateurs/vousetesbannis.php, the (2) elseifvotetxtresultatduvote parameter to utilisateurs/votesresultats.php, and the (3) elseifforumtxtmenugeneraleduforum parameter to moduleajouter/depot/adminforum.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yannick tanguy else if cms 0.6-beta

Exploits

ELSEIF CMS Tested on "Else If version Beta 06" Discovered By : HACKERS PAL Copy rights : HACKERS PAL Website : wwwsoqornet Email Address : security@soqornet These Are Examples iam tiered fetching the injected files :) Remote File inclusion elseif/contenusphp?contenus=[Shell] elseif/utilisateurs/votesphp?tpelseifportalrepertoire=[S ...