Vulnerabilities
Vulnerable Software
Cagintranetworks:  Security Vulnerabilities
Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.
CVSS Score
8.8
EPSS Score
0.004
Published
2017-04-30
XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.
CVSS Score
5.0
EPSS Score
0.007
Published
2015-01-20


Contact Us

Shodan ® - All rights reserved