Skip to main content

Vendor archive

maianscriptworld CVEs

Beta · best-effort

21 CVEs tagged to vendor maianscriptworld1 Critical, 5 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2021-32172

Published Oct 7, 2021

Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-10007

Published Jan 13, 2015

Multiple cross-site scripting (XSS) vulnerabilities in Maian Weblog 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, or (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10006

Published Jan 13, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in Maian Uploader 4.0 allow remote attackers to hijack the authentication of unspecified users for requests that conduct…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10005

Published Jan 13, 2015

Maian Uploader 4.0 allows remote attackers to obtain sensitive information via a request without the height parameter to load_flv.js.php, which reveals the installation path in an…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10004

Published Jan 13, 2015

SQL injection vulnerability in admin/data_files/move.php in Maian Uploader 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7086

Published Aug 26, 2009

Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to admin.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2200

Published May 14, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Maian Weblog 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to admin/index…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2201

Published May 14, 2008

Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/header.php in Maian Recipe 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) header, (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2202

Published May 14, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to upload/ad…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2203

Published May 14, 2008

SQL injection vulnerability in search.php in Maian Search 1.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2204

Published May 14, 2008

Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/header.php in Maian Search 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) header, (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2205

Published May 14, 2008

SQL injection vulnerability in index.php in Maian Music 1.1 allows remote attackers to execute arbitrary SQL commands via the album parameter in an album action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2206

Published May 14, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Maian Music 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter in a search act…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2207

Published May 14, 2008

Cross-site scripting (XSS) vulnerability in admin/index.php in Maian Gallery 2.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a sea…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2208

Published May 14, 2008

SQL injection vulnerability in index.php in Maian Greeting 2.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2209

Published May 14, 2008

Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/header.php in Maian Greeting 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2210

Published May 14, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Maian Support 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script, (2) msg_script2, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2211

Published May 14, 2008

Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/footer.php in Maian Guestbook 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_sc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2212

Published May 14, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Maian Cart 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_adminheader, (2) msg_adminheade…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2213

Published May 14, 2008

Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/footer.php in Maian Links 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1075

Published Feb 29, 2008

Cross-site scripting (XSS) vulnerability in index.php in Maian Cart 1.1 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search comma…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1