Skip to main content

Vendor archive

neocrome CVEs

Beta · best-effort

24 CVEs tagged to vendor neocrome1 Critical, 9 High, 13 Medium, 1 Low, 0 Unrated.

CVE-2012-5916

Published Nov 17, 2012

Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2) docs/upgrade/sedito_convert_…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5915

Published Nov 17, 2012

Neocrome Seditio build 161 and earlier allows remote attackers to obtain sensitive information via direct request to (1) view.php, (2) plugins/contact/lang/contact.en.lang.php, (3…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5914

Published Nov 17, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the sed_import function in system/functions.php in Neocrome Seditio build 160 and 161 allow remote attackers to inject arbit…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-1411

Published Apr 24, 2009

SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the c parameter to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6202

Published Dec 1, 2007

SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] parame…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4057

Published Jul 30, 2007

Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and earlier allows remote authenticated users to upload arbitrary PHP code via a filename ending with (1)…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6835

Published Dec 31, 2006

SQL injection vulnerability in Journal.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the w parameter to j…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6577

Published Dec 15, 2006

SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6343

Published Dec 7, 2006

SQL injection vulnerability in polls.php in Neocrome Seditio 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6344

Published Dec 7, 2006

Multiple unspecified vulnerabilities in Neocrome Seditio 1.10 and earlier have unknown impact and attack vectors related to (1) plugins/ipsearch/ipsearch.admin.php, and (2) pfs/pf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6268

Published Dec 4, 2006

SQL injection vulnerability in system/core/profile/profile.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote authenticated users to execute arbitrary SQL com…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6177

Published Nov 30, 2006

SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2634

Published May 30, 2006

Cross-site scripting (XSS) vulnerability in Neocrome Land Down Under (LDU) in Neocrome Seditio 102 allows remote attackers to inject arbitrary web script or HTML via an HTTP Refer…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2096

Published Apr 29, 2006

plug.php in Land Down Under (LDU) 802 and earlier allows remote attackers to obtain sensitive information via an invalid (1) month or (2) year parameter, which reveals the path in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4711

Published Dec 31, 2005

SQL injection vulnerability in Neocrome Land Down Under (LDU) 801 allows remote attackers to execute arbitrary SQL commands via an HTTP Referer header. NOTE: the provenance of th…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4821

Published Dec 31, 2005

Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parame…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2884

Published Sep 14, 2005

Cross-site scripting (XSS) vulnerability in events.php in Land Down Under (LDU) 801 and earlier allows remote attackers to inject arbitrary web script or HTML via the Description…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2780

Published Sep 2, 2005

Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) allows remote attackers to inject arbitrary web script or HTML via a signature.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2788

Published Sep 2, 2005

Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitrary SQL commands via the c parameter to (1) events.php, (2)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2674

Published Aug 23, 2005

Note: the vendor has disputed this issue. Multiple cross-site scripting (XSS) vulnerabilities in Land Down Under (LDU) 800 allow remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2675

Published Aug 23, 2005

Note: the vendor has disputed this issue. Multiple SQL injection vulnerabilities in Land Down Under (LDU) 800 allow remote attackers to execute arbitrary SQL commands via the (1)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2669

Published Dec 31, 2004

Multiple SQL injection vulnerabilities in Land Down Under (LDU) v701 allow remote attackers to execute arbitrary SQL commands or obtain the installation path via parameters includ…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2038

Published May 29, 2004

Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1315

Published Dec 31, 2003

SQL injection vulnerability in auth.php in Land Down Under (LDU) v601 and earlier allows remote attackers to execute arbitrary SQL commands.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1