Vulnerabilities (CVE)

Filtered by vendor Macromedia Subscribe
Filtered by product Sitespring
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1027 1 Macromedia 1 Sitespring 2023-12-10 7.5 HIGH N/A
Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter.
CVE-2002-1026 1 Macromedia 1 Sitespring 2023-12-10 5.0 MEDIUM N/A
Macromedia Sitespring 1.2.0 (277.1) using Sybase runtime engine 7.0.2.1480 allows remote attackers to cause a denial of service (crash) via a long malformed request to TCP port 2500, possibly triggering a buffer overflow.