Vulnerabilities > Sitebar

DATE CVE VULNERABILITY TITLE RISK
2007-10-29 CVE-2007-5695 Link Following vulnerability in Sitebar 3.3.8
Open redirect vulnerability in command.php in SiteBar 3.3.8 allows remote attackers to redirect users to arbitrary web sites via a URL in the forward parameter in a Log In action.
network
low complexity
sitebar CWE-59
6.4
2007-10-29 CVE-2007-5694 Path Traversal vulnerability in Sitebar 3.3.8
Absolute path traversal vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to read arbitrary files via an absolute path in the dir parameter, a different vulnerability than CVE-2007-5491.
network
low complexity
sitebar CWE-22
6.8
2007-10-29 CVE-2007-5693 Code Injection vulnerability in Sitebar 3.3.8
Eval injection vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to execute arbitrary PHP code via the edit parameter in an upd cmd action, a different vulnerability than CVE-2007-5492.
network
sitebar CWE-94
6.0
2007-10-29 CVE-2007-5692 Cross-Site Scripting vulnerability in Sitebar 3.3.8
Multiple cross-site scripting (XSS) vulnerabilities in SiteBar 3.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to integrator.php; (2) the token parameter in a New Password action, (3) the nid_acl parameter in a Folder Properties action, or (4) the uid parameter in a Modify User action to command.php; or (5) the target parameter to index.php, different vectors than CVE-2006-3320.
network
sitebar CWE-79
4.3
2007-10-17 CVE-2007-5492 Code Injection vulnerability in Sitebar 3.3.8
Static code injection vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to execute arbitrary PHP code via the value parameter.
network
high complexity
sitebar CWE-94
4.6
2007-10-17 CVE-2007-5491 Path Traversal vulnerability in Sitebar 3.3.8
Directory traversal vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to chmod arbitrary files to 0777 via ".." sequences in the lang parameter.
network
low complexity
sitebar CWE-22
critical
9.0
2007-04-18 CVE-2007-2088 Remote Security vulnerability in SiteBar
Multiple PHP remote file inclusion vulnerabilities in Sitebar 3.3.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) writerFile parameter to index.php and the (2) file parameter to Integrator.php.
network
low complexity
sitebar
7.5
2006-06-30 CVE-2006-3320 Cross-Site Scripting vulnerability in SiteBar
Cross-site scripting (XSS) vulnerability in command.php in SiteBar 3.3.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the command parameter.
network
high complexity
sitebar
2.6