Vulnerabilities > Dream4

DATE CVE VULNERABILITY TITLE RISK
2009-02-20 CVE-2008-6210 SQL Injection vulnerability in Dream4 Koobi 4.4/5.4
SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL commands via the img_id parameter in the gallerypic page.
network
low complexity
dream4 CWE-89
7.5
2008-10-29 CVE-2008-4778 SQL Injection vulnerability in Dream4 Koobi CMS 4.3.0
SQL injection vulnerability in the gallery module in Koobi CMS 4.3.0 allows remote attackers to execute arbitrary SQL commands via the galid parameter in a showimages action.
network
low complexity
dream4 CWE-89
7.5
2008-04-30 CVE-2008-2036 SQL Injection vulnerability in Dream4 Koobi 6.25
SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL commands via the poll_id parameter in a poll action.
network
low complexity
dream4 CWE-89
7.5
2008-03-03 CVE-2008-1122 SQL Injection vulnerability in Dream4 Koobi PRO 5.7
SQL injection vulnerability in the downloads module in Koobi Pro 5.7 allows remote attackers to execute arbitrary SQL commands via the categ parameter to index.php.
network
low complexity
dream4 CWE-89
7.5
2006-07-18 CVE-2006-3622 SQL-Injection vulnerability in Dream4 Koobi PRO 5.6
The showtopic module in Koobi Pro CMS 5.6 allows remote attackers to obtain sensitive information via a ' (single quote) in the p parameter, which displays the path in an error message.
network
low complexity
dream4
5.0
2006-07-18 CVE-2006-3621 Input Validation vulnerability in Dream4 Koobi PRO 5.6
SQL injection vulnerability in the showtopic module in Koobi Pro CMS 5.6 allows remote attackers to execute arbitrary SQL commands via the toid parameter.
network
low complexity
dream4
7.5
2006-07-18 CVE-2006-3620 Input Validation vulnerability in Dream4 Koobi PRO 5.6
Cross-site scripting (XSS) vulnerability in the showtopic module in Koobi Pro CMS 5.6 allows remote attackers to inject arbitrary web script or HTML via the toid parameter.
network
high complexity
dream4
2.6
2005-12-30 CVE-2005-4588 Unspecified vulnerability in Dream4 Koobi 5.0
Cross-site scripting (XSS) vulnerability in Koobi 5 allows remote attackers to inject arbitrary web script or HTML via nested, malformed url BBCode tags.
network
dream4
4.3
2005-05-03 CVE-2005-1373 SQL Injection vulnerability in Dream4 Koobi CMS 4.2.3
Multiple SQL injection vulnerabilities in index.php in Dream4 Koobi CMS 4.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) q or (2) p parameters.
network
low complexity
dream4
7.5
2005-05-02 CVE-2005-0890 SQL Injection vulnerability in Dream4 Koobi CMS 4.2.3
SQL injection vulnerability in Dream4 Koobi CMS 4.2.3 allows remote attackers to execute arbitrary SQL commands via the area parameter.
network
low complexity
dream4
7.5