Show filters
25 Total Results
Displaying 21-25 of 25
Sort by:
Attacker Value
Unknown

CVE-2014-5090

Disclosure Date: August 06, 2014 (last updated October 05, 2023)
admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel.
0
Attacker Value
Unknown

CVE-2014-5088

Disclosure Date: August 06, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php.
0
Attacker Value
Unknown

CVE-2013-4137

Disclosure Date: October 11, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
0
Attacker Value
Unknown

CVE-2011-3802

Disclosure Date: September 24, 2011 (last updated October 04, 2023)
StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tpl/index.php and certain other files.
0
Attacker Value
Unknown

CVE-2008-0819

Disclosure Date: February 19, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
0