Show filters
55 Total Results
Displaying 41-50 of 55
Sort by:
Attacker Value
Unknown
CVE-2020-10793
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. NOTE: A contributor to the CodeIgniter framework argues that the issue should not be attributed to CodeIgniter. Furthermore, the blog post reference shows an unknown website built with the CodeIgniter framework but that CodeIgniter is not responsible for introducing this issue because the framework has never provided a login screen, nor any kind of login or user management facilities beyond a Session library. Also, another reporter indicates the issue is with a custom module/plugin to CodeIgniter, not CodeIgniter itself.
0
Attacker Value
Unknown
CVE-2012-1915
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks.
0
Attacker Value
Unknown
CVE-2015-3907
Disclosure Date: July 03, 2019 (last updated November 27, 2024)
CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.
0
Attacker Value
Unknown
CVE-2018-12071
Disclosure Date: June 17, 2018 (last updated November 26, 2024)
A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.
0
Attacker Value
Unknown
CVE-2013-4891
Disclosure Date: February 21, 2018 (last updated November 26, 2024)
The xss_clean function in CodeIgniter before 2.1.4 might allow remote attackers to bypass an intended protection mechanism and conduct cross-site scripting (XSS) attacks via an unclosed HTML tag.
0
Attacker Value
Unknown
CVE-2015-5725
Disclosure Date: February 21, 2018 (last updated November 26, 2024)
SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote attackers to execute arbitrary SQL commands via vectors involving the offset variable.
0
Attacker Value
Unknown
CVE-2017-1000247
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Apache resulting in HTTP Header Injection flaws.
0
Attacker Value
Unknown
CVE-2014-8684
Disclosure Date: September 19, 2017 (last updated November 26, 2024)
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.
0
Attacker Value
Unknown
CVE-2014-8686
Disclosure Date: September 19, 2017 (last updated November 26, 2024)
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.
0
Attacker Value
Unknown
CVE-2016-10131
Disclosure Date: January 12, 2017 (last updated November 25, 2024)
system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from field to insert sendmail command-line arguments.
0