Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2011-4334

Disclosure Date: October 23, 2017 (last updated November 26, 2024)
edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP files via a PHP file with a .gif extension in the userfile parameter.
0
Attacker Value
Unknown

CVE-2011-4333

Disclosure Date: October 23, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) from parameter to index.php or the (2) page_no parameter to recentchanges.php.
Attacker Value
Unknown

CVE-2006-2968

Disclosure Date: June 12, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in PHP Labware LabWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input box (query parameter).
0
Attacker Value
Unknown

CVE-2006-2850

Disclosure Date: June 06, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in recentchanges.php in PHP Labware LabWiki 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the help parameter.
0