2 results (0.003 seconds)

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 1

Multiple cross-site scripting (XSS) vulnerabilities in index.php in BLUEPAGE CMS 2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) whl, (2) var_1, and (3) search parameters. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS)en index.php en BLUEPAGE CMS v2.5 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) parámetro "whl", (2) parámetro "var_1" y (3) parámetro "search". • http://secunia.com/advisories/31968 http://www.majorsecurity.de/index_2.php?major_rls=major_rls53 http://www.securityfocus.com/archive/1/496582/100/0/threaded http://www.securityfocus.com/bid/31312 https://exchange.xforce.ibmcloud.com/vulnerabilities/45321 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.8EPSS: 4%CPEs: 2EXPL: 3

Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. Vulnerabilidad de fijación de sesión en BLUEPAGE CMS v2.5 y anteriores, permite a atacantes remotos secuestrar sesiones web a través del parámetro "PHPSESSID". • https://www.exploit-db.com/exploits/32407 http://secunia.com/advisories/31968 http://www.majorsecurity.de/index_2.php?major_rls=major_rls53 http://www.securityfocus.com/archive/1/496582/100/0/threaded http://www.securityfocus.com/bid/31315 https://exchange.xforce.ibmcloud.com/vulnerabilities/45323 • CWE-287: Improper Authentication •