VYPR

Jsite

by Sclek

CVEs (3)

  • CVE-2008-7301Oct 5, 2011
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in admin/login.php in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2008-3193Jul 16, 2008
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the page parameter to the default URI.

  • CVE-2008-3192Jul 16, 2008
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in index.php in jSite 1.0 OE allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.