VYPR
Vendor
Products
2
CVEs
3
Across products
25
Status
Private

Products

2

Recent CVEs

3
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2009-24430.040.08Jul 13, 2009Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
CVE-2008-32560.030.00Jul 22, 2008SQL injection vulnerability in folder.php in Siteframe CMS 3.2.3 and earlier, and Siteframe Beaumont 5.0.5 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2006-07830.030.06Feb 19, 2006Cross-site scripting (XSS) vulnerability in page.php in in Siteframe Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject arbitrary web script or HTML via the comment_text parameter to the user comment page (/edit/Comment).