Vendorseshtery.she7ataeshtery_cmsany version
Vulnerabilities

eshtery.she7ata eshtery CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2014-2069
Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname in the file parameter to FileManager.aspx.
Published 2018-04-13 · Modified
7.51 PoCEPSS 0.154
CVE-2010-3404
Multiple SQL injection vulnerabilities in eshtery CMS (aka eshtery.com) allow remote attackers to execute arbitrary SQL commands via the (1) Criteria field in an unspecified form related to catlgsearch.aspx or (2) user name to an unspecified form related to adminlogin.aspx.
Published 2010-09-16 · Modified
7.51 PoCEPSS 0.010