Vulnerabilities > Siteatschool

DATE CVE VULNERABILITY TITLE RISK
2008-01-08 CVE-2008-0129 SQL Injection vulnerability in Siteatschool
SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter.
6.8
2007-06-19 CVE-2007-3276 Cross-Site Scripting vulnerability in Siteatschool 2.4.10
Cross-site scripting (XSS) vulnerability in index.php in Site@School (S@S) 2.4.10 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
network
siteatschool
4.3
2006-09-21 CVE-2006-4922 Input Validation vulnerability in Site@School
Unrestricted file upload vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to upload and execute arbitrary files with executable extensions.
network
low complexity
siteatschool
5.0
2006-09-21 CVE-2006-4921 Remote Security vulnerability in Siteatschool 2.4.02
PHP remote file inclusion vulnerability in Site@School (S@S) 2.4.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cmsdir parameter to starnet/modules/include/include.php.
network
low complexity
siteatschool
7.5
2006-09-21 CVE-2006-4920 Input Validation vulnerability in Site@School
Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the cmsdir parameter to (1) starnet/modules/sn_allbum/slideshow.php, and (2) starnet/themes/editable/main.inc.php.
network
low complexity
siteatschool
7.5
2006-09-21 CVE-2006-4919 Input Validation vulnerability in Site@School
Directory traversal vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to read arbitrary files via a ..
network
high complexity
siteatschool
2.6