RSS   Vulnerabilities for 'Weblog'   RSS

2007-05-09
 
CVE-2007-2574

 

 
Directory traversal vulnerability in index.php in Archangel Weblog 0.90.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the index parameter.

 
2006-08-11
 
CVE-2006-4091

CWE-Other
 

 
Multiple cross-site scripting (XSS) vulnerabilities in Archangel Management Archangel Weblog 0.90.02 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Comment section.

 
2006-02-28
 
CVE-2006-0945

CWE-94
 

 
PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter.

 
 
CVE-2006-0944

CWE-Other
 

 
Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1.

 

 >>> Vendor: Archangelmgt 2 Products
Weblog
Archangel weblog


Copyright 2024, cxsecurity.com

 

Back to Top