Skip to main content

Vendor/product archive

mike_helton / aoblogger CVEs

Beta · best-effort

3 CVEs tagged to mike_helton / aoblogger0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2006-0310

Published Jan 19, 2006

Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0311

Published Jan 19, 2006

SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0312

Published Jan 19, 2006

create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1