Robertotto Teamsite Hack Plugin vulnerabilities
2 known vulnerabilities affecting robertotto/teamsite_hack_plugin.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2010-1338P3HIGHCVSS 7.5PoC≤ 3.02010-04-09
CVE-2010-1338 [HIGH] CWE-89 CVE-2010-1338: SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab
SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to execute arbitrary SQL commands via the userid parameter in a modboard action.
nvd
CVE-2010-1339P4MEDIUMCVSS 4.3≤ 3.02010-04-09
CVE-2010-1339 [MEDIUM] CWE-79 CVE-2010-1339: Cross-site scripting (XSS) vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier
Cross-site scripting (XSS) vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to inject arbitrary web script or HTML via the userid parameter in a modboard action, which is not properly handled in a forced SQL error message. NOTE: the provenance of this information is unknown; the
nvd