Etomite is a modestly represented content-management system that occupies a niche position in the vulnerability landscape. Its vulnerability profile is characterized by recurring application-layer input-handling weaknesses—spanning SQL injection, cross-site scripting, improper input validation, path traversal, and OS command injection—that reflect the attack surface inherent to web-facing administrative interfaces and user-supplied content processing. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Etomite over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-7070HIGH Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload and execute arbitrary files v | Mar 2, 2007 | 7.5 | 29 | NO | YES |
CVE-2006-6047MEDIUM Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) | Nov 22, 2006 | 5.8 | 27 | NO | YES |
CVE-2006-3904MEDIUM SQL injection vulnerability in manager/index.php in Etomite CMS 0.6.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the | Jul 27, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-0325HIGH Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/t | Jan 20, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-5242HIGH SQL injection vulnerability in Etomite Content Management System (CMS) before 0.6.1.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Oct 12, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-6048MEDIUM SQL injection vulnerability in index.php in Etomite CMS 0.6.1.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. | Nov 22, 2006 | 6.8 | 18 | NO | NO |
CVE-2011-4264MEDIUM Cross-site scripting (XSS) vulnerability in Etomite before 1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Dec 8, 2011 | 4.3 | 16 | NO | NO |
CVE-2008-0820MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Etomite 0.6.1.4 Final allows remote attackers to inject arbitrary web script or HTML via $_SERVER['PHP_INFO']. NOTE: the v | Feb 19, 2008 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Etomite.
Media articles that mention a CVE ID that affects a product developed by Etomite — matched by CVE ID, not by vendor name.