Skip to main content

Vendor archive

fuzzylime CVEs

Beta · best-effort

10 CVEs tagged to vendor fuzzylime2 Critical, 4 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2009-2177

Published Jun 23, 2009

code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attacks and overwrite arbitrary fi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2176

Published Jun 23, 2009

Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6834

Published Jun 22, 2009

Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the s…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6833

Published Jun 22, 2009

Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a file…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5291

Published Dec 1, 2008

Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3098

Published Sep 24, 2008

Cross-site scripting (XSS) vulnerability in admin/usercheck.php in fuzzylime (cms) before 3.03 allows remote attackers to inject arbitrary web script or HTML via the user paramete…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3164

Published Jul 14, 2008

Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3165

Published Jul 14, 2008

Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary loca…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1405

Published Mar 20, 2008

PHP remote file inclusion vulnerability in code/display.php in fuzzylime (cms) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4805

Published Sep 11, 2007

Directory traversal vulnerability in getgalldata.php in fuzzylime (cms) 3.0 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the p parame…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1