CVE-2006-4106
- EPSS 0.35%
- Veröffentlicht 14.08.2006 20:04:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Cross-site scripting (XSS) vulnerability in blursoft blur6ex 0.3 allows remote attackers to inject arbitrary web script or HTML via a comment title.
CVE-2006-3065
- EPSS 1.33%
- Veröffentlicht 19.06.2006 10:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
SQL injection vulnerability in engine/shards/blog.php in blur6ex 0.3.462 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a proc_reply action in the blog shard. NOTE: This is a similar vulnerability to CVE-2006-1763,...
CVE-2006-1761
- EPSS 0.5%
- Veröffentlicht 13.04.2006 01:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Cross-site scripting vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter, which is not sanitized in the error message. NOTE: the vector in the shard parameter is not ...
CVE-2006-1762
- EPSS 0.99%
- Veröffentlicht 13.04.2006 01:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Directory traversal vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to include arbitrary files via the shard parameter. NOTE: this issue can be exploited to produce resultant XSS when the parameter has XSS manipulations, and pa...
- EPSS 0.62%
- Veröffentlicht 13.04.2006 01:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Multiple SQL injection vulnerabilities in index.php in blur6ex 0.3.452 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a (1) g_reply or (2) g_permaPost action to the blog shard (engine/shards/blog.php), or a (3) g_vi...