VYPR

by Zikula

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2011-33520.000.00Nov 19, 2019Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context of the affected website.
CVE-2011-38260.000.00Sep 24, 2011Zikula 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/voodoodolly/version.php and certain other files.