Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Plume Cms MEDIUM 6.8
CVE-2012-1414

Cross-site request forgery (CSRF) vulnerability in manager/news.php in Plume CMS 1.2.4 and earlier allows remote attackers to hijack the authenticati…

Fix: after 1.2.4
Fix from $1,600 2012-10-07
Plume Cms MEDIUM 6.5
CVE-2009-3418

Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL commands via the m parameter …

Mitigation only
Fix from $1,600 2009-09-25
Plume Cms HIGH 7.5
CVE-2006-7021

PHP remote file inclusion vulnerability in manager/tools/link/dbinstall.php in Plume CMS 1.1.3 allows remote attackers to execute arbitrary PHP code …

No fix yet
Fix from $1,950 2007-02-15
Plume Cms HIGH 7.5
CVE-2006-4533

Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6 and earlier allow remote attackers to execute arbitrary PHP code via the _PX_co…

Fix: after 1.0.6
Fix from $1,950 2006-09-01
Plume Cms HIGH 7.5
CVE-2006-3562

PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager…

No fix yet
Fix from $1,950 2006-07-13
Plume Cms HIGH 7.5
CVE-2006-2645EPSS 6%

PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execute arbitrary code via a URL i…

No fix yet
Fix from $1,950 2006-05-30
Plume Cms MEDIUM 6.8
CVE-2006-0725

PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbit…

Mitigation only
Fix from $1,600 2006-02-16