VendorsFuzzylimefuzzylime_cms3.01
Vulnerabilities

Fuzzylime Fuzzylime CMS 3.01

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2008-3164
Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter. NOTE: it was later reported that 3.01a is also affected.
Published 2008-07-14 · Modified
7.61 PoCEPSS 0.038
CVE-2008-3098
Cross-site scripting (XSS) vulnerability in admin/usercheck.php in fuzzylime (cms) before 3.03 allows remote attackers to inject arbitrary web script or HTML via the user parameter to the login form.
Published 2008-09-24 · Modified
4.31 PoCEPSS 0.020