Vulnerabilities > Kplaylist

DATE CVE VULNERABILITY TITLE RISK
2011-09-23 CVE-2011-3750 Information Exposure vulnerability in Kplaylist 1.8.502
kPlaylist 1.8.502 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by getid3/getid3/write.id3v1.php and certain other files.
network
low complexity
kplaylist CWE-200
5.0
2005-11-26 CVE-2005-3841 Cross-Site Scripting vulnerability in Kplaylist 1.6Build400
Cross-site scripting (XSS) vulnerability in kPlaylist 1.6 (build 400), and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchfor search parameter.
network
kplaylist
4.3