4.7
CVSSv3

CVE-2016-2784

Published: 26/05/2016 Updated: 09/10/2018
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 4.7 | Impact Score: 2.7 | Exploitability Score: 1.6
VMScore: 265
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

CMS Made Simple 2.x prior to 2.1.3 and 1.x prior to 1.12.2, when Smarty Cache is activated, allow remote malicious users to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.

Vulnerable Product Search on Vulmon Subscribe to Product

cmsmadesimple cms made simple 2.1.1

cmsmadesimple cms made simple 2.1

cmsmadesimple cms made simple 1.11.11

cmsmadesimple cms made simple 1.11.10

cmsmadesimple cms made simple 1.11.3

cmsmadesimple cms made simple 1.11.2.1

cmsmadesimple cms made simple 1.10

cmsmadesimple cms made simple 1.9.4.3

cmsmadesimple cms made simple 1.9.4.2

cmsmadesimple cms made simple 1.6.10

cmsmadesimple cms made simple 1.6.9

cmsmadesimple cms made simple 1.6.7

cmsmadesimple cms made simple 1.6.6

cmsmadesimple cms made simple 1.5.3

cmsmadesimple cms made simple 1.5.2

cmsmadesimple cms made simple 1.2.5

cmsmadesimple cms made simple 1.2.4

cmsmadesimple cms made simple 1.1.2

cmsmadesimple cms made simple 1.1.1

cmsmadesimple cms made simple 1.0.2

cmsmadesimple cms made simple 1.0.1

cmsmadesimple cms made simple 1.12.1

cmsmadesimple cms made simple 1.12

cmsmadesimple cms made simple 1.11.7

cmsmadesimple cms made simple 1.11.6

cmsmadesimple cms made simple 1.11

cmsmadesimple cms made simple 1.10.3

cmsmadesimple cms made simple 1.9.3

cmsmadesimple cms made simple 1.9.2

cmsmadesimple cms made simple 1.8.1

cmsmadesimple cms made simple 1.8

cmsmadesimple cms made simple 1.6.3

cmsmadesimple cms made simple 1.6.2

cmsmadesimple cms made simple 1.4.1

cmsmadesimple cms made simple 1.4

cmsmadesimple cms made simple 1.2.1

cmsmadesimple cms made simple 1.2

cmsmadesimple cms made simple 1.0.7

cmsmadesimple cms made simple 1.0.6

cmsmadesimple cms made simple 1.0.5

cmsmadesimple cms made simple 2.0.1.1

cmsmadesimple cms made simple 2.0.1

cmsmadesimple cms made simple 2.0

cmsmadesimple cms made simple 1.11.9

cmsmadesimple cms made simple 1.11.8

cmsmadesimple cms made simple 1.11.2

cmsmadesimple cms made simple 1.11.1

cmsmadesimple cms made simple 1.9.4.1

cmsmadesimple cms made simple 1.9.4

cmsmadesimple cms made simple 1.6.8

cmsmadesimple cms made simple 1.8.2

cmsmadesimple cms made simple 1.6.5

cmsmadesimple cms made simple 1.6.4

cmsmadesimple cms made simple 1.5.1

cmsmadesimple cms made simple 1.5

cmsmadesimple cms made simple 1.2.3

cmsmadesimple cms made simple 1.2.2

cmsmadesimple cms made simple 1.1

cmsmadesimple cms made simple 1.0.8

cmsmadesimple cms made simple 1.0

cmsmadesimple cms made simple 2.1.2

cmsmadesimple cms made simple 1.11.13

cmsmadesimple cms made simple 1.11.12

cmsmadesimple cms made simple 1.11.5

cmsmadesimple cms made simple 1.11.4

cmsmadesimple cms made simple 1.10.2

cmsmadesimple cms made simple 1.10.1

cmsmadesimple cms made simple 1.9.1

cmsmadesimple cms made simple 1.9

cmsmadesimple cms made simple 1.7.1

cmsmadesimple cms made simple 1.7

cmsmadesimple cms made simple 1.6.1

cmsmadesimple cms made simple 1.6

cmsmadesimple cms made simple 1.5.4

cmsmadesimple cms made simple 1.3.1

cmsmadesimple cms made simple 1.3

cmsmadesimple cms made simple 1.1.4.1

cmsmadesimple cms made simple 1.1.3.1

cmsmadesimple cms made simple 1.0.4

cmsmadesimple cms made simple 1.0.3

Exploits

============================================= Web Server Cache Poisoning in CMS Made Simple ============================================= CVE-2016-2784 Product Description =================== CMS Made Simple is a great tool with many plugins to publish content on the Web It aims to be simple to use by end users and to provide a secure and robu ...
CMS Made Simple versions prior to 213 and 1122 suffer from a web server cache poisoning vulnerability ...