- EPSS 0.49%
- Veröffentlicht 25.08.2007 00:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple SQL injection vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navig...
CVE-2007-4523
- EPSS 0.52%
- Veröffentlicht 25.08.2007 00:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_p...
CVE-2007-3524
- EPSS 66.19%
- Veröffentlicht 03.07.2007 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) admin/includes/author_panel_header.php or (2) admin/includes/adm...
CVE-2007-3525
- EPSS 0.31%
- Veröffentlicht 03.07.2007 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Ripe Website Manager 0.8.9 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are o...
CVE-2007-2206
- EPSS 0.54%
- Veröffentlicht 24.04.2007 20:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a leading "<"<" in the ripeformpost parameter.
CVE-2007-2207
- EPSS 1.88%
- Veröffentlicht 24.04.2007 20:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ripeformpost parameter.