Lucene search

K

Xrms Security Vulnerabilities

cve
cve

CVE-2014-5520

SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id parameter to plugins/webform/new-form.php, which is not properly handled by...

8.7AI Score

0.104EPSS

2014-10-26 08:55 PM
19
cve
cve

CVE-2014-5521

plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username...

7.7AI Score

0.017EPSS

2014-09-02 02:55 PM
20
cve
cve

CVE-2008-3948

SQL injection vulnerability in admin/users/self-2.php in XRMS allows remote attackers to execute arbitrary SQL commands and modify name and email fields via unspecified...

8.4AI Score

0.001EPSS

2008-09-05 04:08 PM
22
cve
cve

CVE-2008-3664

Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTML via (1) the real name field, related to the user list; (2) the target parameter to login.php, (3) the title parameter to activities/some.php, (4) the company_name parameter to.....

5.8AI Score

0.002EPSS

2008-09-05 04:08 PM
27
cve
cve

CVE-2008-3399

PHP remote file inclusion vulnerability in activities/workflow-activities.php in XRMS CRM 1.99.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the include_directory...

7.6AI Score

0.008EPSS

2008-07-31 04:41 PM
15
cve
cve

CVE-2008-3398

Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to unspecified components, possibly including login.php. NOTE: this may overlap...

5.8AI Score

0.003EPSS

2008-07-31 04:41 PM
20
cve
cve

CVE-2008-3400

XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, which calls the phpinfo...

6.3AI Score

0.005EPSS

2008-07-31 04:41 PM
23
cve
cve

CVE-2008-1129

Cross-site scripting (XSS) vulnerability in admin/users/self.php in XRMS CRM allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party...

5.5AI Score

0.002EPSS

2008-03-04 12:44 AM
23