Vulnerabilities > Webspot > Webspotblogging > 3.0

DATE CVE VULNERABILITY TITLE RISK
2006-06-06 CVE-2006-2860 Code Injection vulnerability in Webspot Webspotblogging 3.0/3.0.1
PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) inc/logincheck.inc.php, (2) inc/adminheader.inc.php, (3) inc/global.php, or (4) inc/mainheader.inc.php.
network
low complexity
webspot CWE-94
6.4
2006-01-19 CVE-2006-0324 SQL Injection vulnerability in Webspot Webspotblogging 3.0
SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.
network
low complexity
webspot
7.5