← Back

Jcow

jcow

3 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Jcow Cms
jcow_cms
Jcow
jcow

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jcow
1Jcow Cms
Nov 21, 2024
Jan 14, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Scripting (XSS) vulnerability exists in the g parameter to index.php in Jcow CMS 4.2 and earlier.
1Jcow
1Jcow Cms
Nov 21, 2024
Jan 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2.
1Jcow
1Jcow
Apr 29, 2026
Sep 23, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Jcow 4.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/default/page.tpl.php and certain...Show more
Jcow 4.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/default/page.tpl.php and certain other files.Show less