4.3
CVSSv2

CVE-2008-3923

Published: 04/09/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in statistics.php in Content Management Made Easy (CMME) 1.12 allow remote malicious users to inject arbitrary web script or HTML via the (1) page and (2) year parameters in an hstat_year action.

Vulnerable Product Search on Vulmon Subscribe to Product

hans oesterholt cmme 1.12

Exploits

################################################################################################################## [+] CMME 112 (LFI/XSS/CSRF/Download Backup/MkDir) Multiple Remote Vulnerabilities [+] Discovered By SirGod [+] wwwmortal-teamorg [+] Greetz : EMINEM,Ras,Puscas_marin,ToxicBlood,M ...