VendorsBlogcmsblog%5Call versions
Vulnerabilities

Blogcms Blog

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2010-4750
Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allows remote attackers to hijack the authentication of administrators.
Published 2011-03-01 · Modified
6.81 PoCEPSS 0.010
CVE-2010-4749
Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) body parameter to action.php and the (2) amount and (3) action parameters to admin/index.php.
Published 2011-03-01 · Modified
4.31 PoCEPSS 0.020