Vulnerabilities
Vulnerable Software
Hotplug Cms:  Security Vulnerabilities
HotPlug CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to read the admin password and database credentials via a direct request for includes/class/config.inc.
CVSS Score
5.0
EPSS Score
0.003
Published
2006-09-14
Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
CVSS Score
5.8
EPSS Score
0.035
Published
2006-06-23
SQL injection vulnerability in administration/includes/login/auth.php in HotPlug CMS 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.
CVSS Score
7.5
EPSS Score
0.012
Published
2006-06-23


Contact Us

Shodan ® - All rights reserved