VYPR
Vendor

Hotplug Cms

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2006-3189Jun 23, 2006
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

  • CVE-2006-4772Sep 14, 2006
    risk 0.00cvss epss 0.00

    HotPlug CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to read the admin password and database credentials via a direct request for includes/class/config.inc.

  • CVE-2006-3190Jun 23, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in administration/includes/login/auth.php in HotPlug CMS 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.