Astalavista It Engineering

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2006-1293

    Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF).

    Last Modified: Apr 16, 2026
    Published: Mar 19, 2006

    CVE-2005-2416

    Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.

    Last Modified: Apr 16, 2026
    Published: Aug 03, 2005

    CVE-2005-2417

    Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xml.

    Last Modified: Apr 16, 2026
    Published: Aug 03, 2005

    CVE-2005-2415

    Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module.

    Last Modified: Apr 16, 2026
    Published: Aug 03, 2005
    Items Per Page
    Astalavista_It_Engineering Vulnerabilities & Security CVEs | CVE-DB