4.3
CVSSv2

CVE-2009-3803

Published: 27/10/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the status_message parameter to (1) /news, (2) /comment, (3) /forum, (4) /blog, and (5) /tags; the status_message parameter to (6) forum.php, (7) discussion.php, (8) guestbook.php, (9) blog.php, (10) news.php, (11) srv_updates.php, (12) srv_backups.php, (13) srv_twist_prevention.php, (14) srv_tags.php, (15) srv_tags_reindex.php, (16) google_sitemap.php, (17) sitemap_history.php, (18) srv_options.php, (19) locales.php and (20) plugins_wizard.php in _admin/; a crafted IMG BBcode tag in the message body of a (21) forum, (22) guestbook, or (23) comment; (24) the content of an avatar file, which is not properly handled by Internet Explorer; and (25) the loginname parameter (aka username) in _admin/index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

amirocms amiro.cms

amirocms amiro.cms 5.2.3

amirocms amiro.cms 4.2.2.0

amirocms amiro.cms 4.2.1.0

amirocms amiro.cms 5.0.7

amirocms amiro.cms 4.2.5

amirocms amiro.cms 4.2.4

amirocms amiro.cms 4.2.3.0

amirocms amiro.cms 5.2.2

amirocms amiro.cms 5.2

amirocms amiro.cms 4.2.0.5

amirocms amiro.cms 4.0.8.0

Exploits

source: wwwsecurityfocuscom/bid/42430/info AmiroCMS is prone to multiple input-validation vulnerabilities including multiple cross-site scripting issues, an HTML-injection issue, and an information-disclosure issue An attacker may leverage the issues to execute arbitrary script code in the browser of an unsuspecting user in the context ...