Skip to main content

Vendor archive

dream4 CVEs

Beta · best-effort

11 CVEs tagged to vendor dream40 Critical, 7 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2008-6210

Published Feb 20, 2009

SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL commands via the img_id parameter in the gallerypic page.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4778

Published Oct 29, 2008

SQL injection vulnerability in the gallery module in Koobi CMS 4.3.0 allows remote attackers to execute arbitrary SQL commands via the galid parameter in a showimages action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2036

Published Apr 30, 2008

SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL commands via the poll_id parameter in a poll action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1122

Published Mar 3, 2008

SQL injection vulnerability in the downloads module in Koobi Pro 5.7 allows remote attackers to execute arbitrary SQL commands via the categ parameter to index.php. NOTE: it was…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3620

Published Jul 18, 2006

Cross-site scripting (XSS) vulnerability in the showtopic module in Koobi Pro CMS 5.6 allows remote attackers to inject arbitrary web script or HTML via the toid parameter.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-3621

Published Jul 18, 2006

SQL injection vulnerability in the showtopic module in Koobi Pro CMS 5.6 allows remote attackers to execute arbitrary SQL commands via the toid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3622

Published Jul 18, 2006

The showtopic module in Koobi Pro CMS 5.6 allows remote attackers to obtain sensitive information via a ' (single quote) in the p parameter, which displays the path in an error me…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4588

Published Dec 30, 2005

Cross-site scripting (XSS) vulnerability in Koobi 5 allows remote attackers to inject arbitrary web script or HTML via nested, malformed url BBCode tags. NOTE: the provenance of…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1373

Published May 3, 2005

Multiple SQL injection vulnerabilities in index.php in Dream4 Koobi CMS 4.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) q or (2) p parameters.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0890

Published May 2, 2005

SQL injection vulnerability in Dream4 Koobi CMS 4.2.3 allows remote attackers to execute arbitrary SQL commands via the area parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0889

Published Mar 24, 2005

Cross-site scripting (XSS) vulnerability in index.php for Dream4 Koobi CMS 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the area parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1