Vulnerabilities > Jason Hines
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-03-07 | CVE-2005-0698 | Remote File Include vulnerability in Jason Hines PHPWebLog PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that contains the code. | 4.6 |
2001-02-16 | CVE-2001-0088 | Authentication Bypass vulnerability in Jason Hines PHPweblog 0.4.2 common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog. | 7.5 |