4.3
CVSSv2

CVE-2012-6523

Published: 31/01/2013 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in w-CMS 2.01 allow remote malicious users to inject arbitrary web script or HTML via (1) the p parameter in the getMenus function in codes/wcms.php; or the COMMENT parameter in (2) blog.php, (3) guestbook.php, or (4) forum.php in codes/. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

w-cms w-cms 2.01

Exploits

# Exploit Title: W-Cms Multiple Vulnerability # Date: 2012-01-09 # Author: th3g4m3_0v3r # Site:w-cmsinfo/ # Software Link: codegooglecom/p/wcms/ # Dork: intext:"Powered by w-CMS" # Version : [201] # Tested on: Window 7 # Yogesh Kashyap, shubneet goel, w4rl0ckd0wn, Chip, VzAcnY, Razzy, Sayan, Jaggi Panu, Darkgt # wwwh4ck3rin, w ...