Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2009-4805

Disclosure Date: April 23, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the storyid parameter to public/view.php or (2) the kill parameter to admin/remove.php.
0
Attacker Value
Unknown

CVE-2009-4801

Disclosure Date: April 23, 2010 (last updated October 04, 2023)
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts.
0
Attacker Value
Unknown

CVE-2009-4366

Disclosure Date: December 21, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog 1.0 allows remote attackers to inject arbitrary web script or HTML via the yr parameter in a bmonth action.
0
Attacker Value
Unknown

CVE-2009-4365

Disclosure Date: December 21, 2009 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a blog via the add_blog action, (2) approve a comment via the approve_comment action, (3) change administrator information including the password via the admin_opt action, and (4) delete a blog via the delete action.
0
Attacker Value
Unknown

CVE-2009-4364

Disclosure Date: December 21, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog allows remote attackers to inject arbitrary web script or HTML via the cname parameter, related to the act and id parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2009-1626

Disclosure Date: May 12, 2009 (last updated October 04, 2023)
SQL injection vulnerability in public/specific.php in EZ-Blog before Beta 2 20090427, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category parameter.
0