Vulnerabilities > Karl Core

DATE CVE VULNERABILITY TITLE RISK
2010-04-22 CVE-2009-4793 Code Injection vulnerability in Karl Core Bandsite CMS 1.1.4
Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension via an addphotos action to adminpanel/index.php, and then accessing the file via a direct request with an images/gallery/ directory name.
network
karl-core CWE-94
6.0
2010-04-22 CVE-2009-4792 SQL Injection vulnerability in Karl Core Bandsite CMS 1.1.4
SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to execute arbitrary SQL commands via the memid parameter to members.php.
network
low complexity
karl-core CWE-89
7.5