Vulnerabilities
Vulnerable Software
Blueriver:  >> Sava Cms  Security Vulnerabilities
Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 through 5.2, allows remote attackers to read arbitrary files via a .. (dot dot) in the FILEID parameter to the default URI under tasks/render/file/.
CVSS Score
5.0
EPSS Score
0.033
Published
2010-09-29
Cross-site scripting (XSS) vulnerability in index.cfm in Blue River Interactive Group Sava CMS before 5.0.122 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.
CVSS Score
4.3
EPSS Score
0.003
Published
2009-03-06
SQL injection vulnerability in index.cfm in Blue River Interactive Group Sava CMS before 5.0.122 allows remote attackers to execute arbitrary SQL commands via the LinkServID parameter.
CVSS Score
7.5
EPSS Score
0.005
Published
2009-03-06


Contact Us

Shodan ® - All rights reserved