Vulnerabilities
Vulnerable Software
Jaws:  >> Jaws  >> 0.3  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in the NewTerm function in GlossaryModel.php in JAWS 0.4 allows remote attackers to inject arbitrary web script or HTML via the (1) term or (2) description.
CVSS Score
4.3
EPSS Score
0.007
Published
2005-05-02
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, which is compared against the logged session variable by the logged_on function in application.php.
CVSS Score
7.5
EPSS Score
0.036
Published
2004-12-31
Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
CVSS Score
4.3
EPSS Score
0.014
Published
2004-12-31
SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.
CVSS Score
7.5
EPSS Score
0.019
Published
2004-07-29


Contact Us

Shodan ® - All rights reserved