cbcvebase.

Longino Jacome Php-Revista vulnerabilities

4 known vulnerabilities affecting longino/jacome_php-revista.

Total CVEs
4
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2006-4607P3HIGHCVSS 7.5PoCv1.1.22006-09-07
CVE-2006-4607 [HIGH] CVE-2006-4607: admin/index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to bypass authentication admin/index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to bypass authentication controls by setting the ID_ADMIN and SUPER_ADMIN parameters to 1.
nvd
CVE-2006-4605P3HIGHCVSS 7.5PoCv1.1.22006-09-07
CVE-2006-4605 [HIGH] CVE-2006-4605: PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remo PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to execute arbitrary PHP code via the adodb parameter.
nvd
CVE-2006-4606P3HIGHCVSS 7.5PoCv1.1.22006-09-07
CVE-2006-4606 [HIGH] CVE-2006-4606: Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) id_temas parameter in busqueda_tema.php, the (2) cadena parameter in busqueda.php, the (3) id_autor parameter in autor.php, the (4) email parameter in lista.php, and the (5) id_articulo parameter in articulo.php.
nvd
CVE-2006-4608P4MEDIUMCVSS 6.8PoCv1.1.22006-09-07
CVE-2006-4608 [MEDIUM] CVE-2006-4608: Multiple cross-site scripting (XSS) vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote Multiple cross-site scripting (XSS) vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cadena parameter in busqueda.php and the (2) email parameter in lista.php.
nvd
Longino Jacome Php-Revista vulnerabilities | cvebase