Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2008-5965

Disclosure Date: January 26, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to check for the existence of arbitrary files via a .. (dot dot) in the page parameter.
0
Attacker Value
Unknown

CVE-2008-4913

Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.
0
Attacker Value
Unknown

CVE-2008-1860

Disclosure Date: April 17, 2008 (last updated October 04, 2023)
Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default parameter.
0