4.3
CVSSv2

CVE-2014-9146

Published: 14/04/2015 Updated: 15/04/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote malicious users to inject arbitrary web script or HTML via the (1) view, (2) id, (3) page, or (4) app parameter to the default URI or the (5) act parameter to dapur/index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

fiyo fiyo cms 2.0.1.8

Exploits

# Exploit Title: FiyoCMS Multiple Vulnerabilities # Date: 29 March 2015 # Exploit Author: Mahendra # Vendor Homepage: wwwfiyoorg # Software Link: sourceforgenet/projects/fiyo-cms/ # Version: 2018, other version might be vulnerable # Tested : Kali Linux 109a-amd64 # CVE(s): CVE-2014-9145,CVE-2014-9146,CVE-2014-9147,CVE-2014-9148 *Ad ...
FiyoCMS version 2018 suffers from url bypass, cross site scripting, and remote SQL injection vulnerabilities ...