Basic-cms

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 8
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2010-5316

    Cross-site scripting (XSS) vulnerability in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to inject arbitrary web script or HTML via a top_height cookie.

    Last Modified: Apr 12, 2025
    Published: Jan 03, 2015

    CVE-2010-5318

    The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrator's password by specifying the administrator's e-mail address in the email parameter.

    Last Modified: Apr 12, 2025
    Published: Jan 03, 2015

    CVE-2010-5317

    Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before 0.6.7.1 allow remote attackers to execute arbitrary SQL commands via (1) the file_name parameter in an attachment action, (2) the post parameter in a show_comment action, (3) the sys-name parameter in an rssfeed action, or (4) the sys-name parameter in a view action.

    Last Modified: Apr 12, 2025
    Published: Jan 03, 2015

    CVE-2011-3804

    SweetRice 0.7.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by _plugin/tiny_mce/plugins/advimage/images.php.

    Last Modified: Apr 11, 2025
    Published: Sep 24, 2011

    CVE-2010-0695

    Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id parameter.

    Last Modified: Apr 11, 2025
    Published: Feb 23, 2010
    Items Per Page
    Basic-Cms Vulnerabilities & Security CVEs | CVE-DB