Vulnerabilities
Vulnerable Software
Contentcustomizer:  Security Vulnerabilities
dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to obtain sensitive author credentials by making a request with an editauthor action, then reading the value of the newlocalpassword password input field in the HTML source of the resulting page.
CVSS Score
5.0
EPSS Score
0.037
Published
2007-11-05
dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to perform certain privileged actions via a (1) del, (2) delbackup, (3) res, or (4) ren action. NOTE: this issue can be leveraged to conduct cross-site scripting (XSS) and possibly other attacks.
CVSS Score
6.1
EPSS Score
0.004
Published
2007-11-05


Contact Us

Shodan ® - All rights reserved