VendorsConpressoconpresso_cmsany version
Vulnerabilities

Conpresso Conpresso CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2006-5128
SQL injection vulnerability in index.php in Bartels Schoene ConPresso before 4.0.5a allows remote attackers to execute arbitrary SQL commands via the nr parameter.
Published 2006-10-02 · Modified
7.5EPSS 0.014
CVE-2006-5127
Multiple cross-site scripting (XSS) vulnerabilities in Bartels Schoene ConPresso before 4.0.5a allow remote attackers to inject arbitrary web script or HTML via (1) the nr parameter in detail.php, (2) the msg parameter in db_mysql.inc.php, and (3) the pos parameter in index.php.
Published 2006-10-02 · Modified
6.8EPSS 0.017