Vulnerabilities > Agares Media

DATE CVE VULNERABILITY TITLE RISK
2009-02-03 CVE-2008-6040 SQL Injection vulnerability in Agares Media Arcadem PRO 2.700/2.707/2.802
SQL injection vulnerability in index.php in Arcadem Pro 2.700 through 2.802 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter, probably related to includes/articleblock.php.
network
low complexity
agares-media CWE-89
7.5
2008-01-23 CVE-2008-0433 Code Injection vulnerability in Agares Media PHPautovideo
PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadpage parameter, a different vector than CVE-2007-6614.
network
low complexity
agares-media CWE-94
7.5
2008-01-23 CVE-2008-0432 Cross-Site Scripting vulnerability in Agares Media PHPautovideo
Cross-site scripting (XSS) vulnerability in index.php in phpAutoVideo 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
4.3
2008-01-15 CVE-2008-0262 SQL Injection vulnerability in Agares Media PHPautovideo 2.21
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter.
network
low complexity
agares-media CWE-89
7.5
2008-01-03 CVE-2007-6615 Code Injection vulnerability in Agares Media PHPautovideo 2.21
Directory traversal vulnerability in includes/block.php in Agares Media phpAutoVideo 2.21 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the selected_provider parameter.
6.8
2008-01-03 CVE-2007-6614 Code Injection vulnerability in Agares Media PHPautovideo 2.21
PHP remote file inclusion vulnerability in admin/frontpage_right.php in Agares Media phpAutoVideo 2.21 allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter, a related issue to CVE-2007-6542.
6.8
2007-12-27 CVE-2007-6542 Code Injection vulnerability in Agares Media Arcadem
PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter.
network
low complexity
agares-media CWE-94
7.5
2007-08-28 CVE-2007-4552 SQL Injection vulnerability in Agares Media Arcadem 2.0.1
SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL commands via the blockpage parameter.
network
low complexity
agares-media CWE-89
7.5
2007-08-28 CVE-2007-4551 Code Injection vulnerability in Agares Media Arcadem 2.0.1
PHP remote file inclusion vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary PHP code via a URL in the loadpage parameter.
network
low complexity
agares-media CWE-94
7.5