CVE-2012-10034
- EPSS 18.43%
- Veröffentlicht 05.08.2025 20:00:40
- Zuletzt bearbeitet 23.09.2025 18:46:19
ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie parameter. The application fails to sanitize user-supplied input, allowing attackers to traverse directories and read arbitrary files ...
CVE-2009-2438
- EPSS 0.83%
- Veröffentlicht 13.07.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in index.php in the search module in ClanSphere 2009.0 and 2009.0.2 allows remote attackers to inject arbitrary web script or HTML via the text parameter in a list action. NOTE: this might overlap CVE-2008-13...
CVE-2009-2345
- EPSS 0.4%
- Veröffentlicht 07.07.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple SQL injection vulnerabilities in ClanSphere before 2009.0.1 allow remote attackers to execute arbitrary SQL commands via unknown parameters to the gbook module and unspecified other components.
- EPSS 0.56%
- Veröffentlicht 13.03.2009 10:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in ClanSphere before 2008.2.1 allow remote attackers to obtain sensitive information, and possibly have unknown other impact, via vectors related to "javascript insert" and the (1) mods/messages/getusers.php and (...
CVE-2008-1399
- EPSS 0.41%
- Veröffentlicht 20.03.2008 10:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Clansphere 2008 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained ...
- EPSS 2.2%
- Veröffentlicht 30.01.2008 22:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
CVE-2007-5061
- EPSS 0.88%
- Veröffentlicht 24.09.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in mods/banners/navlist.php in Clansphere 2007.4 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php in a banners action.