Show filters
25 Total Results
Displaying 21-25 of 25
Sort by:
Attacker Value
Unknown
CVE-2014-5090
Disclosure Date: August 06, 2014 (last updated October 05, 2023)
admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel.
0
Attacker Value
Unknown
CVE-2014-5088
Disclosure Date: August 06, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php.
0
Attacker Value
Unknown
CVE-2013-4137
Disclosure Date: October 11, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
0
Attacker Value
Unknown
CVE-2011-3802
Disclosure Date: September 24, 2011 (last updated October 04, 2023)
StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tpl/index.php and certain other files.
0
Attacker Value
Unknown
CVE-2008-0819
Disclosure Date: February 19, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
0