Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Jetbox Cms MEDIUM 6.0
CVE-2008-4651

Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby param…

No fix yet
Fix from $1,600 2008-10-22
Jetbox Cms HIGH 7.5
CVE-2007-2685

Multiple SQL injection vulnerabilities in index.php in Jetbox CMS 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2…

No fix yet
Fix from $1,950 2007-05-21
Jetbox Cms MEDIUM 5.0
CVE-2007-2684

Jetbox CMS 2.1 allows remote attackers to obtain sensitive information via (1) a direct request to (a) main_page.php, (b) open_tree.php, and (c) outp…

No fix yet
Fix from $1,600 2007-05-21
Jetbox Cms MEDIUM 6.8
CVE-2007-2732

Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1) path para…

Mitigation only
Fix from $1,600 2007-05-16
Jetbox Cms MEDIUM 6.0
CVE-2007-2733

Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts via unspeci…

Mitigation only
Fix from $1,600 2007-05-16
Jetbox Cms MEDIUM 5.8
CVE-2007-1898

formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and…

Mitigation only
Fix from $1,600 2007-05-16
Jetbox Cms HIGH 7.5
CVE-2006-4737

SQL injection vulnerability in index.php in Jetbox CMS allows remote attackers to inject arbitrary web script or HTML via the item parameter. NOTE: …

Mitigation only
Fix from $1,950 2006-09-13
Jetbox Cms HIGH 7.5
CVE-2006-4738

PHP remote file inclusion vulnerability in phpthumb.php in Jetbox CMS allows remote attackers to execute arbitrary PHP code via a URL in the includes…

Mitigation only
Fix from $1,950 2006-09-13
Jetbox Cms MEDIUM 5.0
CVE-2006-4740

Jetbox CMS allows remote attackers to obtain sensitive information via a direct request for certain files, which reveal the path in an error message.

Mitigation only
Fix from $1,600 2006-09-13
Jetbox Cms HIGH 7.5
CVE-2006-4422EPSS 7%

PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary PH…

No fix yet
Fix from $1,950 2006-08-29
Jetbox Cms HIGH 7.5
CVE-2006-3583

Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator section.

Mitigation only
Fix from $1,950 2006-08-08
Jetbox Cms HIGH 7.5
CVE-2006-3584

Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables via URL par…

Mitigation only
Fix from $1,950 2006-08-08
Jetbox Cms HIGH 7.5
CVE-2006-3586

SQL injection vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to execute arbitrary SQL commands via the (1) frontsession COOKIE parameter…

Mitigation only
Fix from $1,950 2006-08-08
Jetbox Cms HIGH 7.5
CVE-2006-2270EPSS 14%

PHP remote file inclusion vulnerability in includes/config.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary code via a URL in the r…

No fix yet
Fix from $1,950 2006-05-09
Jetbox One Cms MEDIUM 5.0
CVE-2004-1447

Jetbox One 2.0.8 and possibly other versions stores passwords in the database in plaintext, which could allow attackers to gain sensitive information.

Mitigation only
Fix from $1,600 2004-12-31