CVE-2010-5320
- EPSS 0.12%
- Veröffentlicht 03.01.2015 11:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site request forgery (CSRF) vulnerabilities in MemHT Portal 4.0.1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify settings via a configuration action to admin.php, (2) modify articles ...
CVE-2009-0372
- EPSS 2.75%
- Veröffentlicht 30.01.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and an image content type via a user...
CVE-2008-5132
- EPSS 0.91%
- Veröffentlicht 18.11.2008 11:30:02
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in inc/ajax/ajax_rating.php in MemHT Portal 4.0.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.
CVE-2008-4457
- EPSS 1.38%
- Veröffentlicht 07.10.2008 00:31:08
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in inc/inc_statistics.php in MemHT Portal 3.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a stats_res cookie to index.php.
CVE-2008-4164
- EPSS 5.09%
- Veröffentlicht 22.09.2008 18:52:13
- Zuletzt bearbeitet 09.04.2025 00:30:58
cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.