Lucene search

K

Articles Security Vulnerabilities

cve
cve

CVE-2022-1828

The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF...

6.5CVSS

6.3AI Score

0.001EPSS

2022-06-20 11:15 AM
50
7
cve
cve

CVE-2022-1827

The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF...

6.5CVSS

6.3AI Score

0.001EPSS

2022-06-20 11:15 AM
50
6
cve
cve

CVE-2018-1000515

ventrian News-Articles version NewsArticles.00.09.11 contains a XML External Entity (XXE) vulnerability in News-Articles/API/MetaWebLog/Handler.ashx.vb that can result in Attacker can read any file in the server or use smbrelay attack to access to...

7.5CVSS

7.4AI Score

0.006EPSS

2018-06-26 04:29 PM
18
cve
cve

CVE-2017-7627

The "Smart related articles" extension 1.1 for Joomla! does not prevent direct requests to dialog.php (there is a missing _JEXEC...

5.3CVSS

5.3AI Score

0.001EPSS

2017-04-13 03:59 AM
24
cve
cve

CVE-2017-7626

The "Smart related articles" extension 1.1 for Joomla! has XSS in dialog.php (n_art,type in GET...

6.1CVSS

6AI Score

0.001EPSS

2017-04-13 03:59 AM
26
cve
cve

CVE-2017-7628

The "Smart related articles" extension 1.1 for Joomla! has SQL injection in dialog.php (attacker must use search_cats variable in POST method to exploit this...

9.8CVSS

9.7AI Score

0.002EPSS

2017-04-13 03:59 AM
31
cve
cve

CVE-2009-2236

SQL injection vulnerability in yad-admin/login.php in Your Article Directory allows remote attackers to execute arbitrary SQL commands via the txtAdminEmail parameter. NOTE: some of these details are obtained from third party...

8.7AI Score

0.001EPSS

2009-06-27 06:47 PM
22
cve
cve

CVE-2009-2235

SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL commands via the id...

8.7AI Score

0.001EPSS

2009-06-27 06:47 PM
19
cve
cve

CVE-2008-5900

CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAArticles.mdb. NOTE: some of these details are obtained...

6.7AI Score

0.022EPSS

2009-01-12 08:00 PM
24
cve
cve

CVE-2007-3311

SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id...

8.4AI Score

0.004EPSS

2007-06-21 10:30 AM
28
cve
cve

CVE-2006-7052

Multiple PHP remote file inclusion vulnerabilities in DotWidget For Articles (dotwidgeta) 0.2 allow remote attackers to execute arbitrary code via a URL in the (1) file_path parameter to (a) index.php, (b) showcatpicks.php, and (c) showarticle.php; and the (2) admin_header_file and (3)...

8.1AI Score

0.026EPSS

2007-02-24 12:28 AM
25
cve
cve

CVE-2006-4891

SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the key...

8.8AI Score

0.004EPSS

2006-09-19 10:07 PM
22
cve
cve

CVE-2004-1629

Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL...

8.8AI Score

0.002EPSS

2005-02-20 05:00 AM
18