RSS   Podatności dla 'Lightblog'   RSS

2008-02-06
 
CVE-2008-0632

CWE-264
 

 
Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the blog's root directory.

 
2007-10-11
 
CVE-2007-5374

 

 
cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticated users to increase the privileges of any account.

 


Copyright 2024, cxsecurity.com

 

Back to Top