Vulnerabilities > Karl Core
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2010-04-22 | CVE-2009-4793 | Code Injection vulnerability in Karl Core Bandsite CMS 1.1.4 Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension via an addphotos action to adminpanel/index.php, and then accessing the file via a direct request with an images/gallery/ directory name. | 6.0 |
2010-04-22 | CVE-2009-4792 | SQL Injection vulnerability in Karl Core Bandsite CMS 1.1.4 SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to execute arbitrary SQL commands via the memid parameter to members.php. | 7.5 |