VendorsExponent CMSexponent_cms2.0.7
Vulnerabilities

Exponent CMS Exponent CMS 2.0.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2016-2242
Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.
Published 2017-01-23 · Modified
10.0EPSS 0.066
CVE-2013-3294
Multiple SQL injection vulnerabilities in Exponent CMS before 2.2.0 release candidate 1 allow remote attackers to execute arbitrary SQL commands via the (1) src or (2) username parameter to index.php.
Published 2014-02-11 · Modified
7.51 PoCEPSS 0.024