Vulnerabilities (CVE)

Filtered by vendor Yap Subscribe
Filtered by product Yap Blog
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-1038 1 Yap 1 Yap Blog 2024-02-28 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) image_id parameter to comments.php, and remote authenticated administrators to execute arbitrary SQL commands via the (2) user parameter in a modif action to admin/index.php.