Skip to main content

Vendor/product archive

lussumo / vanilla CVEs

Beta · best-effort

9 CVEs tagged to lussumo / vanilla0 Critical, 4 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2010-1337

Published Apr 9, 2010

Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote attackers to execute arbitrary…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1845

Published Jun 1, 2009

Cross-site scripting (XSS) vulnerability in ajax/updatecheck.php in Lussumo Vanilla 1.1.5 and 1.1.7 allows remote attackers to inject arbitrary web script or HTML via the RequestN…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3874

Published Aug 29, 2008

Cross-site scripting (XSS) vulnerability in account.php in Lussumo Vanilla 1.1.5-rc1, 1.1.4, and earlier allows remote authenticated users to inject arbitrary web script or HTML v…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-3758

Published Aug 21, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Lussumo Vanilla 1.1.4 and earlier (1) allow remote attackers to inject arbitrary web script or HTML via the NewPassword para…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3759

Published Aug 21, 2008

Cross-site request forgery (CSRF) vulnerability in ajax/UpdateCheck.php in Vanilla 1.1.4 and earlier has unknown impact and remote attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3760

Published Aug 21, 2008

Cross-site request forgery (CSRF) vulnerability in the sign-out page in Vanilla 1.1.4 and earlier allows remote attackers to hijack the authentication of arbitrary users for reque…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5643

Published Oct 23, 2007

Multiple SQL injection vulnerabilities in Lussumo Vanilla 1.1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the CategoryID parameter to ajax/sortc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5644

Published Oct 23, 2007

Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote attackers to conduct unauthoriz…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3850

Published Jul 25, 2006

PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1