VYPR

Minimal ABlog

by Minimal ABlog

CVEs (3)

  • CVE-2008-6613Apr 6, 2009
    risk 0.03cvss epss 0.02

    uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request.

  • CVE-2008-6612Apr 6, 2009
    risk 0.03cvss epss 0.03

    Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/.

  • CVE-2008-6611Apr 6, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.