Skip to main content

Vendor/product archive

dootzky / oblog CVEs

Beta · best-effort

5 CVEs tagged to dootzky / oblog0 Critical, 0 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2009-4909

Published Jun 25, 2010

admin/index.php in oBlog allows remote attackers to conduct brute-force password guessing attacks via HTTP requests.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4908

Published Jun 25, 2010

Multiple cross-site scripting (XSS) vulnerabilities in oBlog allow remote attackers to inject arbitrary web script or HTML via the (1) commentName, (2) commentEmail, (3) commentWe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4907

Published Jun 25, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in oBlog allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin pa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4904

Published Jun 25, 2010

article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new action.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4903

Published Jun 25, 2010

Cross-site scripting (XSS) vulnerability in index.php in oBlog allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1