Vulnerabilities (CVE)

Filtered by vendor Scripts.oldguy Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-4854 1 Scripts.oldguy 1 Talkback 2024-02-28 7.5 HIGH N/A
addons/import.php in TalkBack 2.3.14 allows remote attackers to execute arbitrary commands via the result parameter.
CVE-2009-4874 1 Scripts.oldguy 1 Talkback 2024-02-28 6.4 MEDIUM N/A
TalkBack 2.3.14 does not properly restrict access to the edit comment feature (comments.php), which allows remote attackers to modify comments.