Total
4 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2004-1962 | 1 Protector System | 1 Protector System | 2024-11-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection filters by using "/**/" sequences in the targeted fields. | |||||
CVE-2004-1961 | 1 Protector System | 1 Protector System | 2024-11-20 | 7.5 HIGH | N/A |
blocker.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection protection and execute limited SQL commands via URL-encoded "'" characters ("%27"). | |||||
CVE-2004-1960 | 1 Protector System | 1 Protector System | 2024-11-20 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in blocker_query.php in Protector System 1.15b1 allows remote attackers to inject arbitrary web script or HTML via the (1) target or (2) portNum parameters. | |||||
CVE-2004-1959 | 1 Protector System | 1 Protector System | 2024-11-20 | 5.0 MEDIUM | N/A |
blocker_query.php in Protector System 1.15b1 for PHP-Nuke allows remote attackers to gain sensitive information via a string in the portNum parameter, which reveals the full path in an error message. |