Skip to main content

Vendor archive

gerrit_van_aaken CVEs

Beta · best-effort

5 CVEs tagged to vendor gerrit_van_aaken0 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2006-3820

Published Jul 25, 2006

Cross-site scripting (XSS) vulnerability in loudblog/index.php in Loudblog before 0.5 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3832

Published Jul 25, 2006

SQL injection vulnerability in index.php in Gerrit van Aaken Loudblog 0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1113

Published Mar 9, 2006

SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1114

Published Mar 9, 2006

Multiple directory traversal vulnerabilities in Loudblog before 0.42 allow remote attackers to read or include arbitrary files via a .. (dot dot) and trailing %00 (NULL) byte in t…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0565

Published Feb 6, 2006

PHP remote file include vulnerability in inc/backend_settings.php in Loudblog 0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the $GLOBALS[path]…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1