Show filters
53 Total Results
Displaying 51-53 of 53
Sort by:
Attacker Value
Unknown
CVE-2008-5221
Disclosure Date: November 25, 2008 (last updated October 04, 2023)
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters.
0
Attacker Value
Unknown
CVE-2008-2228
Disclosure Date: May 14, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep parameter.
0
Attacker Value
Unknown
CVE-2006-5768
Disclosure Date: November 06, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Cyberfolio 2.0 RC1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the av parameter to (1) msg/view.php, (2) msg/inc_message.php, (3) msg/inc_envoi.php, and (4) admin/incl_voir_compet.php.
0