Geeklog

Geeklog

31 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 84%
  • Veröffentlicht 22.05.2007 00:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_system] parameter.

  • EPSS 4.75%
  • Veröffentlicht 07.02.2007 11:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_libraries] parameter. NOTE: this might be a vulnerability in MVCnPHP rather t...

  • EPSS 12.32%
  • Veröffentlicht 02.12.2006 02:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a URL in the _CONF[path] parameter to (1) links/functions.inc, (2) polls/functions.inc, (3) spamx/BlackList.Examine.class.php, (4) ...

  • EPSS 0.64%
  • Veröffentlicht 21.07.2006 14:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in Geeklog 1.4.0sr4 and earlier, and 1.3.11sr6 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors when validating comments in (1) lib-comment.php (1.4.0sr4) or ...

Exploit
  • EPSS 15.21%
  • Veröffentlicht 06.07.2006 20:05:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when...

Exploit
  • EPSS 0.6%
  • Veröffentlicht 31.05.2006 10:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

SQL injection vulnerability in Geeklog 1.4.0sr2 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to story submission.

Exploit
  • EPSS 1.04%
  • Veröffentlicht 31.05.2006 10:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

SQL injection vulnerability in admin/auth.inc.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the loginname parameter.

Exploit
  • EPSS 1.4%
  • Veröffentlicht 31.05.2006 10:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to inject arbitrary HTML or web script via the image argument in a show action.

Exploit
  • EPSS 1.07%
  • Veröffentlicht 31.05.2006 10:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Geeklog 1.4.0sr2 and earlier allows remote attackers to obtain the full installation path via a direct request and possibly invalid arguments to (1) layout/professional/functions.php or (2) getimage.php.

  • EPSS 0.38%
  • Veröffentlicht 07.03.2006 23:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Unspecified vulnerability in the session handling for Geeklog 1.4.x before 1.4.0sr2, 1.3.11 before 1.3.11sr5, 1.3.9 before 1.3.9sr5, and possibly earlier versions allows attackers to gain privileges as arbitrary users via unknown vectors.