Arabless

Saphplesson

6 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.31%
  • Published 20.08.2009 17:30:09
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in admin/login.php in SaphpLesson 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cp_username parameter, related to an error in the CleanVar function in includes/fu...

  • EPSS 1.03%
  • Published 06.06.2006 20:06:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in saphplesson 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) forumid parameter in add.php and (2) lessid parameter in show.php.

  • EPSS 0.6%
  • Published 10.05.2006 02:14:00
  • Last modified 03.04.2025 01:03:51

SaphpLesson 3.0 does not initialize array variables, which allows remote attackers to obtain the full path via an non-array (1) hrow parameter to (a) show.php or (b) index.php; the (2) Lsnrow parameter to (c) showcat.php; or the (3) rows parameter to...

  • EPSS 1.46%
  • Published 10.05.2006 02:14:00
  • Last modified 03.04.2025 01:03:51

Multiple SQL injection vulnerabilities in SaphpLesson 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the Find parameter in (a) search.php, and the (2) LID and (3) Rate parameters in (b) misc.php.

  • EPSS 0.44%
  • Published 11.04.2006 23:02:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in search.php in SaphpLesson 3.0 allows remote attackers to inject arbitrary web script or HTML via the Word parameter. NOTE: it is possible that this issue is resultant from SQL injection.

Exploit
  • EPSS 0.42%
  • Published 28.03.2006 20:02:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter.