Webspot Webspotblogging vulnerabilities
2 known vulnerabilities affecting webspot/webspotblogging.
Total CVEs
2
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2006-0324P3HIGHCVSS 7.5PoCv3.02006-01-19
CVE-2006-0324 [HIGH] CVE-2006-0324: SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL
SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.
nvd
CVE-2006-2860P3MEDIUMCVSS 6.4PoCv3.0v3.0.12006-06-06
CVE-2006-2860 [MEDIUM] CWE-94 CVE-2006-2860: PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute
PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) inc/logincheck.inc.php, (2) inc/adminheader.inc.php, (3) inc/global.php, or (4) inc/mainheader.inc.php. NOTE: some of these vectors were also reported for 3.0 in a separate disclosure.
nvd