Mywebland
Mywebland Mybloggie: vulnerabilidades y CVE
Mywebland Mybloggie tiene 21 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2007-1899 | Media (5.1) | 0.92% | — | 9 jul 2008 | Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote… |
| CVE-2007-3650 | Media (5.3) | 1.2% | — | 9 jul 2008 | myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through index.php; (2) a direct request to common.php; and (3) a mode array… |
| CVE-2008-3080 | Media (5.1) | 0.41% | — | 9 jul 2008 | Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administrators. NOTE: this can be leveraged to execute SQL commands by also… |
| CVE-2007-3194 | Crítica (9.8) | 1.6% | — | 12 jun 2007 | Multiple PHP remote file inclusion vulnerabilities in myBloggie 2.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the bloggie_root_path parameter to (1) config.php; (2) db.php, (3) template.php,… |
| CVE-2007-3003 | Alta (7.5) | 1.0% | — | 4 jun 2007 | Multiple SQL injection vulnerabilities in myBloggie 2.1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) year parameter to index.php in a viewuser action, different… |
| CVE-2007-0353 | Media (6.8) | 2.7% | — | 19 ene 2007 | Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO string. |
| CVE-2006-4042 | Alta (7.5) | 1.9% | — | 9 ago 2006 | Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) title, (2) url, (3) excerpt, or (4) blog_name… |
| CVE-2006-4043 | Media (5) | 1.7% | — | 9 ago 2006 | index.php in myWebland myBloggie 2.1.4 and earlier allows remote attackers to obtain sensitive information via a query that only specifies the viewdate mode, which reveals the table prefix in a SQL error message. |
| CVE-2006-3905 | Alta (7.5) | 1.5% | — | 27 jul 2006 | SQL injection vulnerability in Webland MyBloggie 2.1.3 allows remote attackers to execute arbitrary SQL commands via the (1) post_id parameter in index.php and (2) search function. |
| CVE-2006-3903 | Media (5.8) | 2.1% | — | 27 jul 2006 | CRLF injection vulnerability in (1) index.php and (2) admin.php in myWebland MyBloggie 2.1.3 allows remote attackers to hijack sessions and conduct cross-site scripting (XSS) attacks via a cookie. |
| CVE-2006-2859 | Alta (7.5) | 1.8% | — | 6 jun 2006 | PHP remote file inclusion vulnerability in MyBloggie 2.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mybloggie_root_path parameter to (1) admin.php or (2) scode.php. NOTE: this… |
| CVE-2006-2269 | Media (4.3) | 1.7% | — | 9 may 2006 | Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag. |
| CVE-2006-1205 | Media (4.3) | 2.9% | — | 14 mar 2006 | Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) confirmredirect and (2) post_id parameters in… |
| CVE-2005-4225 | Alta (7.5) | 2.0% | — | 14 dic 2005 | Multiple "potential" SQL injection vulnerabilities in myBloggie 2.1.3 beta might allow remote attackers to execute arbitrary SQL commands via (1) the category parameter in add.php, (2) the cat_desc parameter in… |
| CVE-2005-3153 | Alta (7.5) | 1.5% | — | 5 oct 2005 | login.php in myBloggie 2.1.3 beta and earlier allows remote attackers to bypass a whitelist regular expression and conduct SQL injection attacks via a username parameter with SQL after a null character, which causes the… |
| CVE-2005-2838 | Alta (7.5) | 1.4% | — | 7 sept 2005 | SQL injection vulnerability in login.php in myBloggie 2.1.3-beta and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. |
| CVE-2005-1499 | Alta (7.5) | 2.7% | — | 11 may 2005 | delcomment.php in myBloggie 2.1.1 allows remote attackers to delete arbitrary comments by modifying the comment_id parameter. |
| CVE-2005-1498 | Media (4.3) | 3.6% | — | 11 may 2005 | Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) year parameter in viewmode.php, or the (2) cat_id, (3) month_no, or (4)… |
| CVE-2005-1497 | Media (5) | 1.4% | — | 11 may 2005 | index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message. |
| CVE-2005-1500 | Alta (7.5) | 2.5% | — | 11 may 2005 | Multiple SQL injection vulnerabilities in myBloggie 2.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the keyword parameter in search.php; or (2) the date_no parameter in viewdate mode, (3) the… |
| CVE-2005-1140 | Media (4.3) | 0.99% | — | 15 abr 2005 | Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the comments. |