Vulnerabilities
Vulnerable Software
Grayscalecms:  Security Vulnerabilities
BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain copies of the database via a direct request.
CVSS Score
5.0
EPSS Score
0.026
Published
2009-08-24
Cross-site scripting (XSS) vulnerability in merchandise.php in BandSite CMS 1.1.4 allows remote attackers to inject arbitrary HTML or web script via the type parameter.
CVSS Score
4.3
EPSS Score
0.013
Published
2009-08-24
Cross-site request forgery (CSRF) vulnerability in BandSite CMS 1.1.4 allows remote attackers to hijack the authentication of administrators and force a logout via adminpanel/logout.php.
CVSS Score
6.8
EPSS Score
0.001
Published
2009-08-24


Contact Us

Shodan ® - All rights reserved