VendorsCitysoftcommunity_enterprise4.x
Vulnerabilities

Citysoft Community Enterprise 4.x

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2005-4384
CitySoft Community Enterprise 4.x allows remote attackers to obtain the full path of the server via an invalid (1) fuseaction parameter to index.cfm and (2) documentid parameter to document/docWindow.cfm.
Published 2005-12-20 · Modified
6.4EPSS 0.014
CVE-2005-4383
Cross-site scripting (XSS) vulnerability in index.cfm in CitySoft Community Enterprise 4.x allows remote attackers to inject arbitrary web script or HTML via the (1) presentationSite, (2) docPublishYear, (3) docDescription, (4) publishState, (5) docAuthor, (6) docTitle, (7) subTopic, (8) topic, (9) topicRadio, (10) topicOnly, (11) startrow, and (12) sortby parameters.
Published 2005-12-20 · Modified
4.3EPSS 0.012