Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Exponent Cms MEDIUM 5.0
CVE-2007-2252

Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive information …

No fix yet
Fix from $1,600 2007-04-25
Exponent Cms MEDIUM 6.4
CVE-2006-4963EPSS 7%

Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot…

No fix yet
Fix from $1,600 2006-09-23
Exponent HIGH 10.0
CVE-2005-3764

The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with un…

Mitigation only
Fix from $1,950 2005-11-22
Exponent HIGH 7.5
CVE-2005-3762

SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows remote attackers to execute …

No fix yet
Fix from $1,950 2005-11-22
Exponent HIGH 7.5
CVE-2005-3765

Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute …

Mitigation only
Fix from $1,950 2005-11-22
Exponent MEDIUM 5.0
CVE-2005-3763

Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackers to obtai…

Mitigation only
Fix from $1,600 2005-11-22
Exponent MEDIUM 5.0
CVE-2005-3766

Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though certain p…

Mitigation only
Fix from $1,600 2005-11-22
Exponent MEDIUM 5.0
CVE-2005-3767

Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and execute PH…

Mitigation only
Fix from $1,600 2005-11-22
Exponent MEDIUM 5.0
CVE-2005-0310

Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info.php, (3)…

Mitigation only
Fix from $1,600 2005-05-02