VendorsAnchor CMSanchor_cms0.9.1
Vulnerabilities

Anchor CMS Anchor CMS 0.9.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2015-5687
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.
Published 2015-10-05 · Modified
7.5EPSS 0.025
CVE-2014-9182
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.
Published 2014-12-02 · Modified
4.3EPSS 0.010