4.3
CVSSv2

CVE-2010-1482

Published: 12/05/2010 Updated: 13/05/2010
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in admin/editprefs.php in the backend in CMS Made Simple (CMSMS) prior to 1.7.1 might allow remote malicious users to inject arbitrary web script or HTML via the date_format_string parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cmsmadesimple cms made simple 1.2

cmsmadesimple cms made simple 1.1.2

cmsmadesimple cms made simple 0.10

cmsmadesimple cms made simple 1.6.7

cmsmadesimple cms made simple 1.6

cmsmadesimple cms made simple 1.5.3

cmsmadesimple cms made simple 1.2.5

cmsmadesimple cms made simple 1.2.3

cmsmadesimple cms made simple 1.0.7

cmsmadesimple cms made simple 1.0.4

cmsmadesimple cms made simple 0.11.1

cmsmadesimple cms made simple 0.10.4

cmsmadesimple cms made simple 1.1

cmsmadesimple cms made simple 1.0

cmsmadesimple cms made simple 0.11

cmsmadesimple cms made simple 1.4.1

cmsmadesimple cms made simple 1.3

cmsmadesimple cms made simple 1.6.5

cmsmadesimple cms made simple 1.6.4

cmsmadesimple cms made simple 1.6.3

cmsmadesimple cms made simple 1.6.2

cmsmadesimple cms made simple 1.6.1

cmsmadesimple cms made simple 1.2.1

cmsmadesimple cms made simple 1.1.4.1

cmsmadesimple cms made simple 1.1.1

cmsmadesimple cms made simple 1.0.8

cmsmadesimple cms made simple 1.5

cmsmadesimple cms made simple 1.4

cmsmadesimple cms made simple 0.13

cmsmadesimple cms made simple 0.12

cmsmadesimple cms made simple 1.0.5

cmsmadesimple cms made simple 1.0.2

cmsmadesimple cms made simple 1.5.1

cmsmadesimple cms made simple 1.3.1

cmsmadesimple cms made simple 1.0.1

cmsmadesimple cms made simple 0.12.2

cmsmadesimple cms made simple 0.12.1

cmsmadesimple cms made simple 0.11.2

cmsmadesimple cms made simple 1.2.2

cmsmadesimple cms made simple 1.1.3.1

cmsmadesimple cms made simple

cmsmadesimple cms made simple 1.6.6

cmsmadesimple cms made simple 1.5.4

cmsmadesimple cms made simple 1.5.2

cmsmadesimple cms made simple 1.2.4

cmsmadesimple cms made simple 1.0.6

cmsmadesimple cms made simple 1.0.3

cmsmadesimple cms made simple 0.10.3

Exploits

O2 Classic Router suffers from cross site request forgery and cross site scripting vulnerabilities ...
CMS Made Simple versions 170 and below suffer from a cross site scripting vulnerability ...