Skip to main content

Vendor/product archive

alexander_palmo / simple_php_blog CVEs

Beta · best-effort

12 CVEs tagged to alexander_palmo / simple_php_blog0 Critical, 3 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2011-5029

Published Dec 29, 2011

Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.7.0 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4421

Published Dec 24, 2009

Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated users to include and execute arbitrary local files via a ..…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5071

Published Sep 24, 2007

Incomplete blacklist vulnerability in upload_img_cgi.php in Simple PHP Blog before 0.5.1 allows remote attackers to upload dangerous files and execute arbitrary code, as demonstra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5072

Published Sep 24, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog (SPHPBlog) before 0.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web sc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1243

Published Mar 15, 2006

Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3473

Published Nov 3, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2787

Published Sep 2, 2005

comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2733

Published Aug 30, 2005

upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2192

Published Jul 11, 2005

SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0214

Published May 2, 2005

Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1135

Published May 2, 2005

Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1137

Published May 2, 2005

Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to obtain sensitive information via a direct request to sb_functions.php, which leaks the full pathname in a PHP error mes…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1