Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fipsforum MEDIUM 5.0
CVE-2010-0765

fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database …

No fix yet
Fix from $1,600 2010-03-02
Fipscms Light MEDIUM 5.0
CVE-2009-2022EPSS 5%

fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the dat…

No fix yet
Fix from $1,600 2009-06-09
Fipscms HIGH 7.5
CVE-2008-3722

SQL injection vulnerability in forum/neu.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the kat parameter. NOTE: t…

No fix yet
Fix from $1,950 2008-08-20
Fipscms Light HIGH 7.5
CVE-2008-3417

SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the r pa…

Fix: after 2.1
Fix from $1,950 2008-07-31
Fipscms HIGH 7.5
CVE-2008-2124

SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL commands via the lg parameter.

No fix yet
Fix from $1,950 2008-05-09
Fipscms HIGH 7.5
CVE-2007-2561

SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter, a different …

Mitigation only
Fix from $1,950 2007-05-09
Fipsshop HIGH 7.5
CVE-2006-6243

Multiple SQL injection vulnerabilities in index.asp in FipsSHOP allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) did p…

Fix: after 5.10
Fix from $1,950 2006-12-04
Fipscms HIGH 7.5
CVE-2006-6115

SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.

Fix: after 4.5
Fix from $1,950 2006-11-26
Fipsforum HIGH 7.5
CVE-2006-6116

SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parame…

Fix: after 2.6
Fix from $1,950 2006-11-26
Fipsgallery HIGH 7.5
CVE-2006-6117

SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the which para…

Fix: after 1.5
Fix from $1,950 2006-11-26
Fipsgallery MEDIUM 6.8
CVE-2006-3022

Cross-site scripting (XSS) vulnerability in zoom.php in fipsGallery 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML vi…

Fix: after 1.5
Fix from $1,600 2006-06-15