CVE-2021-27969
- EPSS 0.21%
- Veröffentlicht 23.03.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:58:56
Dolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter.
CVE-2013-3638
- EPSS 0.39%
- Veröffentlicht 06.02.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 01:54:02
SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL commands via the 'pathes' parameter in 'categories.php'.
CVE-2014-4333
- EPSS 0.22%
- Veröffentlicht 19.06.2014 14:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the members[] param...
CVE-2014-3810
- EPSS 0.36%
- Veröffentlicht 19.06.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in administration/profiles.php in BoonEx Dolphin 7.1.4 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the members[] parameter. NOTE: this can be exploited by remote attackers ...
CVE-2012-0873
- EPSS 7.34%
- Veröffentlicht 23.02.2012 20:07:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) explain parameter to explanation.php or the (2) photos_only, (3) online_only, or (4) mode par...
- EPSS 0.28%
- Veröffentlicht 23.09.2011 23:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Dolphin 7.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xmlrpc/BxDolXMLRPCProfileView.php and certain other files.
CVE-2008-3167
- EPSS 5.53%
- Veröffentlicht 14.07.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dir[plugins] parameter to (a) HTMLSax3.php and (b) safehtml.php in...
CVE-2006-5410
- EPSS 0.89%
- Veröffentlicht 20.10.2006 14:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP remote file inclusion vulnerability in templates/tmpl_dfl/scripts/index.php in BoonEx Dolphin 5.2 allows remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter. NOTE: it is possible that this issue overlaps CVE-2006-4...
CVE-2006-4189
- EPSS 5.68%
- Veröffentlicht 17.08.2006 01:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple PHP remote file inclusion vulnerabilities in Dolphin 5.1 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) index.php, (2) aemodule.php, (3) browse.php, (4) cc.php, (5) click.php, (6) faq.php, (7)...