Myiosoft Easybookmarker vulnerabilities
4 known vulnerabilities affecting myiosoft/easybookmarker.
Total CVEs
4
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2008-5651P3HIGHCVSS 7.5PoCv4.02008-12-17
CVE-2008-5651 [HIGH] CWE-89 CVE-2008-5651: SQL injection vulnerability in plugins/bookmarker/bookmarker_backend.php in MyioSoft EasyBookMarker
SQL injection vulnerability in plugins/bookmarker/bookmarker_backend.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the Parent parameter.
nvd
CVE-2008-5652P3HIGHCVSS 7.5PoCv4.02008-12-17
CVE-2008-5652 [HIGH] CWE-89 CVE-2008-5652: SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyBookMarker 4.0 all
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter. NOTE: some of these details are obtained from third party information.
nvd
CVE-2008-5655P3HIGHCVSS 7.5PoCv4.02008-12-17
CVE-2008-5655 [HIGH] CVE-2008-5655: Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to exec
Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified vectors, possibly to (a) plugins/bookmarker/bookmarker_backend.php or (b) ajaxp.php, different vectors than CVE-2008-5654. NOTE: the provenance of this information
nvd
CVE-2008-3380P4MEDIUMCVSS 4.3PoCv4.02008-07-30
CVE-2008-3380 [MEDIUM] CWE-79 CVE-2008-3380: Cross-site scripting (XSS) vulnerability in ajaxp_backend.php in MyioSoft EasyBookMarker 4.0 trial e
Cross-site scripting (XSS) vulnerability in ajaxp_backend.php in MyioSoft EasyBookMarker 4.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the rs parameter.
nvd