RSS   Vulnerabilities for 'Bookmark4u'   RSS

2007-02-22
 
CVE-2006-7025

 

 
SQL injection vulnerability in admin/config.php in Bookmark4U 2.0 and 2.1 allows remote attackers to inject arbitrary SQL command via the sqlcmd parameter.

 
2006-06-06
 
CVE-2006-2877

CWE-Other
 

 
PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.

 
2003-12-31
 
CVE-2003-1253

 

 
PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to (1) dbase.php, (2) config.php, or (3) common.load.php.

 

 >>> Vendor: Sangwan kim 2 Products
Bookmark4u
Phpindexpage


Copyright 2024, cxsecurity.com

 

Back to Top