Lucene search

K

Contenido Security Vulnerabilities

cve
cve

CVE-2005-4132

Unspecified "security leak" vulnerability in Contenido before 4.6.4, when register_globals is on and allow_url_fopen is true, has unspecified impact and attack vectors. NOTE: it is likely that this is a PHP remote file include vulnerability.

6.8AI Score

0.006EPSS

2005-12-09 11:03 AM
96
cve
cve

CVE-2006-5380

Remote file inclusion vulnerability in Contenido CMS allows remote attackers to execute arbitrary PHP code via a URL in the contenido_path parameter to (1) cms/dbfs.php or (2) cms/front_content.php. NOTE: CVE disputes this issue for version 4.6.15, because $contenido_path is set to a static value

7.7AI Score

0.01EPSS

2006-10-18 10:00 AM
23
cve
cve

CVE-2006-5381

Contenido CMS stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain database credentials and other information via a direct request to (1) db_msql.inc, (2) db_mssql.inc, (3) db_mysqli.inc, (4) db_oci8.inc, (5) db_odbc.inc, (6) db_oracle.i...

6.7AI Score

0.005EPSS

2006-10-18 10:00 AM
21
cve
cve

CVE-2008-2911

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, and (3) username parameters.

5.8AI Score

0.002EPSS

2008-06-30 06:24 PM
23
cve
cve

CVE-2008-2912

Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenido_path parameter to (a) contenido/backend_search.php; the (2) cfg[path][contenido] parameter to (b) move_articles.php, (c) move_old_stats.php, ...

7.6AI Score

0.01EPSS

2008-06-30 06:24 PM
21
cve
cve

CVE-2014-9433

Multiple cross-site scripting (XSS) vulnerabilities in cms/front_content.php in Contenido before 4.9.6, when advanced mod rewrite (AMR) is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) idart, (2) lang, or (3) idcat parameter.

5.9AI Score

0.007EPSS

2014-12-31 10:59 PM
25