Vulnerabilities > Knusperleicht

DATE CVE VULNERABILITY TITLE RISK
2006-12-23 CVE-2006-6721 HTML Injection vulnerability in Knusperleicht Shoutbox 2.6
Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) sbNick or (2) sbKommentar parameter.
network
knusperleicht
6.8
2006-08-07 CVE-2006-4008 Remote File Include vulnerability in Knusperleicht FAQ 1.0
PHP remote file inclusion vulnerability in index.php in Knusperleicht Faq 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the faq_path parameter.
network
low complexity
knusperleicht
7.5
2006-08-07 CVE-2006-4007 Remote File Include vulnerability in Knusperleicht Guestbook 3.5
PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter.
network
low complexity
knusperleicht
7.5
2006-08-05 CVE-2006-3989 Remote File Include vulnerability in Knusperleicht Shoutbox 3.0.2
PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sb_include_path parameter.
network
high complexity
knusperleicht
5.1
2006-08-05 CVE-2006-3988 Remote File Include vulnerability in Knusperleicht Newsreporter 1.0
PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the news_include_path parameter.
network
high complexity
knusperleicht
5.1
2006-08-05 CVE-2006-3987 Remote File Include vulnerability in Knusperleicht FileManager DWL_Download
Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) dwl_download_path or (2) dwl_include_path parameters.
network
high complexity
knusperleicht
5.1
2006-08-05 CVE-2006-3986 Remote File Include vulnerability in Knusperleicht NewsLetter
PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NL_PATH parameter.
network
low complexity
knusperleicht
7.5
2006-08-05 CVE-2006-3982 Remote File Include vulnerability in Knusperleicht Quickie 0.2
PHP remote file inclusion vulnerability in quickie.php in Knusperleicht Quickie, probably 0.2, allows remote attackers to execute arbitrary PHP code via a URL in the QUICK_PATH parameter.
network
low complexity
knusperleicht
7.5
2005-05-02 CVE-2005-1220 Information Disclosure vulnerability in Shoutbox Script
Shoutbox SCRIPT 3.0.2 and earlier allows remote attackers to obtain sensitive information via a direct request to db/settings.dat, which displays usernames and password hashes.
network
low complexity
knusperleicht
7.5