VendorsAstalavista It Engineeringcontrexxall versions
Vulnerabilities

Astalavista It Engineering Contrexx

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2005-2415
Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module.
Published 2005-08-03 · Modified
7.5EPSS 0.016
CVE-2005-2417
Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xml.
Published 2005-08-03 · Modified
5.0EPSS 0.018
CVE-2005-2416
Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.
Published 2005-08-03 · Modified
4.3EPSS 0.018
CVE-2006-1293
Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF).
Published 2006-03-19 · Modified
4.3EPSS 0.018