cbcvebase.

Maianscriptworld Maian Uploader vulnerabilities

4 known vulnerabilities affecting maianscriptworld/maian_uploader.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2014-10004P3HIGHCVSS 7.5v4.02015-01-13
CVE-2014-10004 [HIGH] CWE-89 CVE-2014-10004: SQL injection vulnerability in admin/data_files/move.php in Maian Uploader 4.0 allows remote attacke SQL injection vulnerability in admin/data_files/move.php in Maian Uploader 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
nvd
CVE-2008-2202P4MEDIUMCVSS 4.3PoCv4.02008-05-14
CVE-2008-2202 [MEDIUM] CWE-79 CVE-2008-2202: Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to upload/admin/index.php in a search action, the (2) msg_charset and (3) msg_header9 parameters to admin/inc/header.php, and the (4) keywords parameter to index.php in a search action.
nvd
CVE-2014-10006P4MEDIUMCVSS 6.8v4.02015-01-13
CVE-2014-10006 [MEDIUM] CWE-352 CVE-2014-10006: Multiple cross-site request forgery (CSRF) vulnerabilities in Maian Uploader 4.0 allow remote attack Multiple cross-site request forgery (CSRF) vulnerabilities in Maian Uploader 4.0 allow remote attackers to hijack the authentication of unspecified users for requests that conduct cross-site scripting (XSS) attacks via the width parameter to (1) uploader/admin/js/load_flv.js.php or (2) uploader/js/load_flv.js.php.
nvd
CVE-2014-10005P4MEDIUMCVSS 5.0v4.02015-01-13
CVE-2014-10005 [MEDIUM] CWE-200 CVE-2014-10005: Maian Uploader 4.0 allows remote attackers to obtain sensitive information via a request without the Maian Uploader 4.0 allows remote attackers to obtain sensitive information via a request without the height parameter to load_flv.js.php, which reveals the installation path in an error message.
nvd
Maianscriptworld Maian Uploader vulnerabilities | cvebase