VYPR

Link Up Gold

by Php Web Scripts

CVEs (3)

  • CVE-2009-4349Dec 17, 2009
    risk 0.03cvss epss 0.02

    Cross-site request forgery (CSRF) vulnerability in administration/administrators.php in Link Up Gold 5.0 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

  • CVE-2005-4231Dec 14, 2005
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in Link Up Gold 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) link parameter to tell_friend.php, (2) phrase[] parameter to search.php in a search_links_advanced action, and the (3) direction or (4) sort parameter to articles.php.

  • CVE-2005-4230Dec 14, 2005
    risk 0.00cvss epss 0.00

    SQL injection vulnerability in poll.php in Link Up Gold 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the number parameter.