Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Zanfi Solutions Subscribe
Filtered by product Zanfi Cms Lite
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4158 1 Zanfi Solutions 1 Zanfi Cms Lite 2017-09-28 6.8 MEDIUM N/A
Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) flag and (2) inc parameters.
CVE-2008-4159 1 Zanfi Solutions 2 Jaw Portal, Zanfi Cms Lite 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitrary SQL commands via the page (pageid) parameter.
CVE-2004-2195 1 Zanfi Solutions 1 Zanfi Cms Lite 2017-07-10 5.0 MEDIUM N/A
PHP remote file inclusion vulnerability in index.php in Zanfi CMS lite 1.1 allows remote attackers to execute arbitrary PHP code via the inc parameter.
CVE-2004-2196 1 Zanfi Solutions 1 Zanfi Cms Lite 2017-07-10 5.0 MEDIUM N/A
Zanfi CMS lite 1.1 allows remote attackers to obtain the full path of the web server via direct requests without required arguments to (1) adm_pages.php, (2) corr_pages.php, (3) del_block.php, (4) del_page.php, (5) footer.php, (6) home.php, and others.