Vulnerabilities (CVE)

Filtered by vendor Myknowledgequest Subscribe
Filtered by product Knowledgequest
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-1727 1 Myknowledgequest 1 Knowledgequest 2024-11-21 7.5 HIGH N/A
KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts.
CVE-2008-1726 1 Myknowledgequest 1 Knowledgequest 2024-11-21 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kqid parameter to (a) articletext.php and (b) articletextonly.php and the (2) username parameter to (c) logincheck.php.