Show filters
55 Total Results
Displaying 41-50 of 55
Sort by:
Attacker Value
Unknown

CVE-2020-10793

Disclosure Date: March 23, 2020 (last updated February 21, 2025)
CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. NOTE: A contributor to the CodeIgniter framework argues that the issue should not be attributed to CodeIgniter. Furthermore, the blog post reference shows an unknown website built with the CodeIgniter framework but that CodeIgniter is not responsible for introducing this issue because the framework has never provided a login screen, nor any kind of login or user management facilities beyond a Session library. Also, another reporter indicates the issue is with a custom module/plugin to CodeIgniter, not CodeIgniter itself.
Attacker Value
Unknown

CVE-2012-1915

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks.
Attacker Value
Unknown

CVE-2015-3907

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.
0
Attacker Value
Unknown

CVE-2018-12071

Disclosure Date: June 17, 2018 (last updated November 26, 2024)
A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.
0
Attacker Value
Unknown

CVE-2013-4891

Disclosure Date: February 21, 2018 (last updated November 26, 2024)
The xss_clean function in CodeIgniter before 2.1.4 might allow remote attackers to bypass an intended protection mechanism and conduct cross-site scripting (XSS) attacks via an unclosed HTML tag.
0
Attacker Value
Unknown

CVE-2015-5725

Disclosure Date: February 21, 2018 (last updated November 26, 2024)
SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote attackers to execute arbitrary SQL commands via vectors involving the offset variable.
0
Attacker Value
Unknown

CVE-2017-1000247

Disclosure Date: November 17, 2017 (last updated November 26, 2024)
British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Apache resulting in HTTP Header Injection flaws.
0
Attacker Value
Unknown

CVE-2014-8684

Disclosure Date: September 19, 2017 (last updated November 26, 2024)
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.
0
Attacker Value
Unknown

CVE-2014-8686

Disclosure Date: September 19, 2017 (last updated November 26, 2024)
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.
0
Attacker Value
Unknown

CVE-2016-10131

Disclosure Date: January 12, 2017 (last updated November 25, 2024)
system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from field to insert sendmail command-line arguments.
0