4.3
CVSSv2

CVE-2008-2496

Published: 28/05/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Quate CMS 0.3.4 allow remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) login.php, and (3) credits.php in admin/, and (4) upgrade/index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

quate quate cms 0.3.4

Exploits

Digital Security Research Group [DSecRG] Advisory #DSECRG-08-030 Application: Quate CMS Versions Affected: 034 Vendor URL: wwwquatenet/ Bugs: RFI, Multiple LFI, Directory traversal, Multiple XSS Exploits: YES Reported: ...