Vulnerabilities (CVE)

Filtered by vendor Siteframe Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-2443 1 Siteframe 1 Siteframe Cms 2023-12-10 5.0 MEDIUM N/A
Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
CVE-2008-3256 1 Siteframe 2 Siteframe Beaumont, Siteframe Cms 2023-12-10 7.5 HIGH N/A
SQL injection vulnerability in folder.php in Siteframe CMS 3.2.3 and earlier, and Siteframe Beaumont 5.0.5 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2006-0783 1 Siteframe 1 Siteframe Beaumont 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in page.php in in Siteframe Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject arbitrary web script or HTML via the comment_text parameter to the user comment page (/edit/Comment).