RSS   Vulnerabilities for 'LORE'   RSS

2007-04-12
 
CVE-2007-2021

CWE-Other
 

 
Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to third_party/phpmailer/class.phpmailer.php or the (2) get_plugin_file_path parameter to third_party/smarty/libs/plugins/function.html_checkboxes.php. NOTE: the affected files might be from other software packages, so this might not be a vulnerability in Lore itself. NOTE: (1) might be the same issue as CVE-2006-5734.4.

 
2006-06-06
 
CVE-2006-2836

 

 
SQL injection vulnerability in comment.php in Pineapple Technologies Lore 1.5.6 and earlier allows remote attackers to execute arbitrary SQL commands via the article_id parameter.

 
2005-12-04
 
CVE-2005-3988

 

 
SQL injection vulnerability in article.php in Pineapple Technologies Lore 1.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

 

 >>> Vendor: Pineapple technologies 2 Products
LORE
Quizshock


Copyright 2024, cxsecurity.com

 

Back to Top