| CVE-2006-4719 | | 0.04 | — | 0.13 | | Sep 12, 2006 | Multiple PHP remote file inclusion vulnerabilities in MyABraCaDaWeb 1.0.3, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) index.php or (2) pop.php. |
| CVE-2003-1548 | | 0.04 | — | 0.06 | | Dec 31, 2003 | MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the installation path in an error message. |
| CVE-2003-1549 | | 0.00 | — | 0.01 | | Dec 31, 2003 | Cross-site scripting (XSS) vulnerability in header.php in MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the ma_kw parameter. |