Cross-site scripting (XSS) vulnerability in page.php in in Siteframe Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject arbitrary web script or HTML via the comment_text parameter to the user comment page (/edit/Comment).
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| siteframe | siteframe_beaumont | 5.0.1 |
| siteframe | siteframe_beaumont | 5.0.1a |
| siteframe | siteframe_beaumont | 5.0.2 |
SQL injection vulnerability in folder.php in Siteframe CMS 3.2.3 and earlier, and Siteframe Beaumont 5.0.5 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| siteframe | siteframe_cms | 2.1+0001 |
| siteframe | siteframe_beaumont | 5.0.1 |
| siteframe | siteframe_cms | 3.2.1 |
| siteframe | siteframe_beaumont | 5.0.1a |
| siteframe | siteframe_cms | 2.4 |
| siteframe | siteframe_cms | 2.2.1 |
| siteframe | siteframe_cms | 2.2.2 |
| siteframe | siteframe_cms | 2.2.0 |
| siteframe | siteframe_cms | 2.3.2 |
| siteframe | siteframe_cms | 2.3 |
| siteframe | siteframe_cms | 3.0.2 |
| siteframe | siteframe_cms | 3.0.1 |
| siteframe | siteframe_cms | * |
| siteframe | siteframe_beaumont | * |
| siteframe | siteframe_cms | 3.2.2 |
| siteframe | siteframe_cms | 2.0.2 |
| siteframe | siteframe_cms | 3.1.0 |
| siteframe | siteframe_cms | 2.0.2+0005 |
| siteframe | siteframe_beaumont | 5.0.2 |
Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| siteframe | siteframe_cms | 3.2.3 |
| siteframe | siteframe_cms | 3.2.2 |
| siteframe | siteframe_cms | 3.2.1 |