Vulnerabilities > Blojsom

DATE CVE VULNERABILITY TITLE RISK
2006-09-15 CVE-2006-4830 Directory Traversal vulnerability in Blojsom 2.30
Directory traversal vulnerability in EditBlogTemplatesPlugin.java in David Czarnecki Blojsom 2.30 allows remote attackers to have an unknown impact by sending an HTTP request with a certain value of blogTemplate.
network
low complexity
blojsom
critical
10.0
2006-09-15 CVE-2006-4829 Cross-Site Scripting vulnerability in Blojsom 2.31
Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki Blojsom 2.31 allow remote attackers to inject arbitrary web script or HTML via the (1) blog-category-description, (2) blog-entry-title, (3) rss-enclosure-url, (4) technorati-tagsi, or (5) blog-category-name parameter in a blog post.
network
blojsom
6.8