Vulnerabilities (CVE)

Filtered by vendor Mike Helton Subscribe
Filtered by product Aoblogger
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0310 1 Mike Helton 1 Aoblogger 2024-02-28 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.
CVE-2006-0312 1 Mike Helton 1 Aoblogger 2024-02-28 5.0 MEDIUM N/A
create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.
CVE-2006-0311 1 Mike Helton 1 Aoblogger 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.