MidnightBSD

Advisories for the_media_shoppe_berhad

CVE-2005-4721 MEDIUM

Cross-site scripting (XSS) vulnerability in search.cfm in tmsPUBLISHER 3.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
the_media_shoppe_berhad tmspublisher 3.3
CVE-2005-4722 MEDIUM

_Request_Message.cfm in tmsPUBLISHER 3.3 allows remote attackers to obtain sensitive information via an invalid id argument to pagename.cfm, which reveals the installation path in an error message.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
the_media_shoppe_berhad tmspublisher 3.0
the_media_shoppe_berhad tmspublisher 3.3