RSS   Vulnerabilities for 'Kplaylist'   RSS

2011-09-23
 
CVE-2011-3750

CWE-200
 

 
kPlaylist 1.8.502 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by getid3/getid3/write.id3v1.php and certain other files.

 
2005-11-26
 
CVE-2005-3841

 

 
Cross-site scripting (XSS) vulnerability in kPlaylist 1.6 (build 400), and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchfor search parameter.

 


Copyright 2019, cxsecurity.com

 

Back to Top