Identifier
|
Related Record |
Severity
|
Date Published
|
Description | Versions Affected |
---|---|---|---|---|---|
CVE-2008-3948 | High | Sep 05, 2008 | SQL injection vulnerability in admin/users/self-2.php in XRMS allows remote attackers to execute arbitrary SQL commands and modify name and email field more... |
1.99.2
|
|
CVE-2008-3400 | Medium | Jul 31, 2008 | XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, which calls the phpinfo function. |
1.99.2
|
|
CVE-2008-3399 | Medium | Jul 31, 2008 | PHP remote file inclusion vulnerability in activities/workflow-activities.php in XRMS CRM 1.99.2, when register_globals is enabled, allows remote attac more... |
1.99.2
|
|
CVE-2008-3398 | Low | Jul 31, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2 allow remote attackers to inject arbitrary web script or HTML via the msg parame more... |
1.99.2
|