VYPR
Vendor

Easypagecms

Products
2
CVEs
3
Across products
3
Status
Private

Products

2

Recent CVEs

3
  • CVE-2006-6486Dec 12, 2006
    risk 0.00cvss epss 0.00

    SQL injection vulnerability in EasyPage allows remote attackers to execute arbitrary SQL commands via unspecified vectors in sptrees/default.aspx, possibly involving the docId parameter. NOTE: this issue appears to have been disputed by a third party researcher, stating that SQL injection is not possible. However, insufficient details were provided to evaluate the dispute.

  • CVE-2006-4862Sep 19, 2006
    risk 0.00cvss epss 0.00

    SQL injection vulnerability in default.aspx in easypage allows remote attackers to execute arbitrary SQL commands via the srch parameter in the Search page.

  • CVE-2005-3854Nov 27, 2005
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in index.php in EasyPageCMS allows remote attackers to inject arbitrary web script or HTML via the cat parameter.