Iss Oberlausitz operates a content management system called Bluepage CMS that serves as the affected product in its vulnerability profile. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iss Oberlausitz over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38923CRITICAL BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' field using a Time-based blind SLEEP payload. | Apr 3, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-38922CRITICAL BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'users-cookie-settings' token using a Time-based blind SLEEP pa | Apr 3, 2023 | 9.8 | 29 | NO | NO |
CVE-2008-6039MEDIUM Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | Feb 3, 2009 | 6.8 | 27 | NO | YES |
CVE-2008-6027MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in BLUEPAGE CMS 2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) whl, (2) | Feb 3, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iss Oberlausitz.
Media articles that mention a CVE ID that affects a product developed by Iss Oberlausitz — matched by CVE ID, not by vendor name.