Vulnerabilities (CVE)

Filtered by vendor Sitex Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-1236 1 Sitex 1 Sitex 2024-02-28 6.4 MEDIUM N/A
sitex allows remote attackers to obtain sensitive information via a request with a numerical value for the (1) sxMonth[] or (2) sxYear[] parameter to calendar.php, or the (3) page[] parameter to calendar_events.php, which reveals the path in various error messages.
CVE-2007-5141 1 Sitex 1 Sitex Cms 2024-02-28 6.8 MEDIUM N/A
SQL injection vulnerability in search.php in SiteX CMS 0.7.3 Beta allows remote attackers to execute arbitrary SQL commands via the search parameter.