VendorsToenda Software Developmenttoendacmsany version
Vulnerabilities

Toenda Software Development Toendacms any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2006-2799
Cross-site scripting (XSS) vulnerability in content_footer.php in toendaCMS 0.7.0 allows remote attackers to inject arbitrary web scripts or HTML via the print_url variable. NOTE: the provenance of this information is unknown; the details are obtained solely from third party sources.
Published 2006-06-03 · Modified
6.8EPSS 0.013
CVE-2005-3550
Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the id_user parameter.
Published 2005-11-16 · Modified
5.01 PoCEPSS 0.063
CVE-2005-3551
toendaCMS before 0.6.2 stores user account and session data in the web root directory, which allows remote attackers to obtain sensitive information via a direct request to the appropriate XML file.
Published 2005-11-16 · Modified
5.0EPSS 0.014
CVE-2005-4277
Cross-site scripting (XSS) vulnerability in index.php in toendaCMS before 0.7 Beta allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Published 2005-12-16 · Modified
4.3EPSS 0.014
CVE-2006-4016
Cross-site scripting (XSS) vulnerability in /toendaCMS in toendaCMS stable 1.0.3 and earlier, and unstable 1.1 and earlier, allows remote attackers to inject arbitrary web script or HTML via the s parameter.
Published 2006-08-07 · Modified
4.3EPSS 0.013