CVE-2012-0933: Acidcat CMS
Low severity, CVSS 2.6. EPSS: 3.8% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in Acidcat CMS 3.5.1, 3.5.2, 3.5.6, and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin_colors.asp, (2) admin_config.asp, and (3) admin_cat_add.asp in admin/.
Affected products
- Acidcat Acidcat CMS: version 3.5.1 only; version 3.5.2 only; version 3.5.6 only
Published 2012-01-29. Last modified 2026-06-16.