Vulnerabilities
Vulnerable Software
X2engine:  >> X2crm  Security Vulnerabilities
Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.9 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a .pht extension.
CVSS Score
7.5
EPSS Score
0.112
Published
2015-09-29
Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the model parameter to index.php/admin/editor.
CVSS Score
4.3
EPSS Score
0.004
Published
2013-09-30
Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php/admin/translationManager.
CVSS Score
8.5
EPSS Score
0.093
Published
2013-09-30


Contact Us

Shodan ® - All rights reserved