Efiction Project

Efiction

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.6%
  • Veröffentlicht 11.12.2005 21:03:00
  • Zuletzt bearbeitet 16.06.2026 22:18:17

Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter in a viewlist action to titles.php.

Exploit
  • EPSS 3.44%
  • Veröffentlicht 11.12.2005 21:03:00
  • Zuletzt bearbeitet 16.06.2026 22:18:18

Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titles.php and (2) the username.

Exploit
  • EPSS 2.18%
  • Veröffentlicht 11.12.2005 21:03:00
  • Zuletzt bearbeitet 16.06.2026 22:18:18

Multiple SQL injection vulnerabilities in eFiction 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) let parameter in a viewlist action to authors.php and (2) sid parameter to viewstory.php.

Exploit
  • EPSS 2.05%
  • Veröffentlicht 11.12.2005 21:03:00
  • Zuletzt bearbeitet 16.06.2026 22:18:18

SQL injection vulnerability in eFiction 1.1 allows remote attackers to execute arbitrary SQL commands via the uid parameter to viewuser.php.

Exploit
  • EPSS 7.9%
  • Veröffentlicht 11.12.2005 21:03:00
  • Zuletzt bearbeitet 16.06.2026 22:18:18

The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a .php extension that contains a GIF header, which passe...

Exploit
  • EPSS 1.76%
  • Veröffentlicht 11.12.2005 21:03:00
  • Zuletzt bearbeitet 16.06.2026 22:18:18

eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error message.

Exploit
  • EPSS 1.76%
  • Veröffentlicht 11.12.2005 21:03:00
  • Zuletzt bearbeitet 16.06.2026 22:18:18

eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which executes the PHP phpinfo function.