RSS   Vulnerabilities for 'Skadate online dating software'   RSS

2010-03-26
 
CVE-2009-4739

CWE-94
 

 
PHP remote file inclusion vulnerability in index.php in SkaDate Dating allows remote attackers to execute arbitrary PHP code via a URL in the language_id parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences.

 
2010-03-15
 
CVE-2009-4700

CWE-22
 

 
Directory traversal vulnerability in index.php in SkaDate Dating allows remote attackers to read arbitrary files via a .. (dot dot) in the layout parameter.

 
 
CVE-2009-4699

CWE-79
 

 
Multiple cross-site scripting (XSS) vulnerabilities in SkaDate Dating allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin/auth.php and (2) file_uploader.php.

 
2007-10-09
 
CVE-2007-5299

 

 
Multiple directory traversal vulnerabilities in SkaDate 5.0 and 6.0, and possibly later versions such as 6.482, allow remote attackers to read arbitrary files via a .. (dot dot) in the view_mode parameter to (1) featured_list.php and (2) online_list.php in member/.

 


Copyright 2024, cxsecurity.com

 

Back to Top