RSS   Vulnerabilities for 'Php link directory'   RSS

2009-07-07
 
CVE-2008-6851

 

 
SQL injection vulnerability in page.php in PHP Link Directory (phpLD) 3.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the name parameter.

 
2007-01-25
 
CVE-2007-0529

CWE-Other
 

 
Cross-site scripting (XSS) vulnerability in index.html (aka the administration page) in PHP Link Directory (phpLD) 3.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted link, which is triggered when the administrator uses the "Validate Links" functionality.

 


Copyright 2024, cxsecurity.com

 

Back to Top