Phpbms
Kreotek · 3 CVEs
CVE-2009-3756
MEDIUM
phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.…
Oct 22, 2009
CVE-2009-3755
MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in phpBMS 0.96 allow remote attackers to inject arbitrary web scrip…
Oct 22, 2009
CVE-2009-3754
HIGH
Multiple SQL injection vulnerabilities in phpBMS 0.96 allow remote attackers to execute arbitrary SQL commands via the…
Oct 22, 2009
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2009-3756 | phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsear… | MEDIUM | 2.29% | Oct 22, 2009 |
| CVE-2009-3755 | Multiple cross-site scripting (XSS) vulnerabilities in phpBMS 0.96 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index… | MEDIUM | 1.25% | Oct 22, 2009 |
| CVE-2009-3754 | Multiple SQL injection vulnerabilities in phpBMS 0.96 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to modules/bms/invoices… | HIGH | 0.95% | Oct 22, 2009 |
Showing 1 to 3 of 3 CVEs