Vulnerabilities > Myknowledgequest
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-04-11 | CVE-2008-1727 | Improper Authentication vulnerability in Myknowledgequest Knowledgequest 2.5/2.6 KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts. | 7.5 |
2008-04-11 | CVE-2008-1726 | SQL Injection vulnerability in Myknowledgequest Knowledgequest 2.6 Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kqid parameter to (a) articletext.php and (b) articletextonly.php and the (2) username parameter to (c) logincheck.php. | 6.8 |