📦

tinymce_compressor_php

Vendor: moxiecode

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 4 Total Indexed
Avg. EPSS 3.86% Exploit Prob.
Latest CVE CVE-2005-4599 Dec 31

Security Vulnerability Index

Page 1 / 1
4.3 CVSS

Cross-site scripting (XSS) vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to inject arbitrary web script or HTML via the index parameter.

EPSS: 1.71%
6.4 CVSS
CVE-2005-4600
Exploit Found

Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter.

EPSS: 6.01%