MidnightBSD

Advisories for bjsintay

CVE-2009-1846 HIGH

Multiple directory traversal vulnerabilities in SiteX 0.7.4 Build 418 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the THEME_FOLDER parameter to (1) Corporate/homepage.php, (2) Fusion/homepage.php, (3) Joombo/homepage.php, (4) Streamline/homepage.php, and (5) Structure/homepage.php in themes/.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
bjsintay sitex *
bjsintay sitex 0.7.4_beta
bjsintay sitex 0.7.3
bjsintay sitex 0.7_beta
bjsintay sitex 0.7.3_beta
bjsintay sitex 0.7.2_beta
bjsintay sitex 0.6.4_beta
bjsintay sitex 0.7.1_beta
CVE-2010-1343 HIGH

SQL injection vulnerability in photo.php in SiteX 0.7.4 beta allows remote attackers to execute arbitrary SQL commands via the albumid parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
bjsintay sitex 0.7.4