← Back

Isweb

isweb

Vendor: Isweb • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Isweb
1Isweb
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CMS ISWEB 3.5.3 is vulnerable to directory traversal and local file download, as demonstrated by moduli/downloadFile.php?file=oggetto_documenti/../.././inc/config.php (one can take the control of the application because...Show more
CMS ISWEB 3.5.3 is vulnerable to directory traversal and local file download, as demonstrated by moduli/downloadFile.php?file=oggetto_documenti/../.././inc/config.php (one can take the control of the application because credentials are present in that config.php file).Show less
1Isweb
1Isweb
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CMS ISWEB 3.5.3 is vulnerable to multiple SQL injection flaws. An attacker can inject malicious queries into the application and obtain sensitive information.
1Isweb
1Isweb
Nov 21, 2024
Aug 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CMS ISWEB 3.5.3 has XSS via the ordineRis, sezioneRicerca, or oggettiRicerca parameter to index.php.